Meta’s Data: Meta’s WhatsApp Fix for View Once and its Impact on MetadataTL;DR: Following our discovery and disclosure of Meta’s WhatsApp View Once media privacy issue, WhatsApp has silently updated its Servers…Dec 9, 2024Dec 9, 2024
Debugging Okta’s AWS SAMLA short write up on the actual debugging of Okta SAML for AWS.Nov 10, 2024Nov 10, 2024
I Know Which Device You Used Last Summer: Fingerprinting WhatsApp Users’ DevicesWhatsApp leaks user device setup (# of devices, mobile or not) and Operating System info (Android, iPhone / iOS, Windows, Mac)Oct 15, 2024Oct 15, 2024
WhatsApp View Once Privacy Issue Initial Fix Assessment: The Good, the Bad and The UglyTL;DR: Following our recent discovery and disclosure of Meta’s WhatsApp View Once media privacy issue, WhatsApp have silently updated its…Sep 16, 2024Sep 16, 2024
Once and Forever: WhatsApp’s View Once Functionality is BrokenMeta’s WhatsApp suggests using “View once” media for privacy. We discovered attackers can and actually do bypass this limitation.Sep 9, 20241Sep 9, 20241
Revealing the Inner Structure of AWS Session TokensTL;DR: A world first reverse engineering analysis of AWS Session Tokens. Prior to our research these tokens were a complete black box…Jul 25, 20241Jul 25, 20241
Hi Meta, WhatsApp with Integrity?TL;DR: Meta’s WhatsApp suffers from an integrity issue that allows attackers to create an inconsistent world view on victims’ multi-device…May 21, 2024May 21, 2024
Published inZengo WalletBad Randomness: Protecting Against Cryptography’s Perfect CrimeTL;DR: Black Hat Asia invited Zengo’s research team to present research on a critical but often overlooked vulnerability in cryptography…May 8, 20242May 8, 20242
The Ambassador protocol: Multi-device E2EE with PrivacyTL;DR: In this blog we present the ambassador protocol, our new cryptographic solution to enable End-to-End Encryption (E2EE) in the…Mar 3, 2024Mar 3, 2024
Unnecessary Evil: Multi-Device Instant Messaging can be privateTL;DR: Contrary to Meta’s WhatsApp claims, it is possible to have an Instant Messaging service with End-to-End Encryption (E2EE) in the…Jan 21, 2024Jan 21, 2024