Skip to content

Opening book details…

About this document

Injection Attacks on E2E Encrypted Apps by Painfull is a document available to read on EtoBox.

This document investigates injection attacks on end-to-end (E2E) encrypted messaging applications like WhatsApp and Signal, where adversaries can send chosen messages to target clients, potentially revealing confidential information through encrypted backups. The authors present various attack vectors that exploit vulnerabilities in backup designs, such as attachment deduplication and compression methods, which allow attackers to infer metadata and message content without needing access to decryption keys.

Author
Painfull
Language
EN