Software Developer Says Mega Master Keys Are Retrievable
hypnosec writes that software developer Michael Koziarski has released a bookmarklet
"which he claims has the ability to reveal Mega users' master key. Koziarski went on to claim that Mega has the ability to grab its users' keys and use them to access their files. Dubbed MegaPWN, the tool not only reveals a user's master key, but also gives away a user's RSA private key exponent. 'MEGApwn is a bookmarklet that runs in your web browser and displays your supposedly secret MEGA master key, showing that it is not actually encrypted and can be retrieved by MEGA or anyone else with access to your computer without you knowing,' reads an explanation about the bookmarklet on its official page."
I don't think there are many people who would trust Mega anyway. I mean, we all pretty much feel the US (and the New Zealand) governments overreached and broke laws when they begin prosecuting Kim DotCom, but most people realize that the guy is a self-aggrandizing scam artist and charlatan. Does anyone actually trust his stuff?
Once you enter your password into a website, the website can do anything that you can do.... Duh
Yes, mega doesn't have your key stored on their servers.
Yes, at any point while you're logged in they can change this fact, or they can just log your password, or whatever.
Doesn't matter what the website is, you have to trust it to use it.
How is this news?
I don't get it, why is this a big deal? This just displays your local storage in your web browser.
Some people die at 25 and aren't buried until 75. -Benjamin Franklin
Unless Im misreading it, this can be summarized as follows:
* Coder has discovered that, in order to encrypt data, your computer must have access to the encryption key
* Further, if someone has root access to your machine, they can get your encryption key.
Wow. What a discovery.
MEGA and anyone else with access to your computer can see this, and use it to decrypt any file you upload.
Wait, someone with access to my computer has access to things that my computer has access to? WOW!
The issue is that it's 'conceptually possible' for Ubuntu to ship a package in the base system that uploads your keys to Canonical's servers. I can give you a script that you run on RHEL and it'll show decrypted ssh, ssl, and gpg keys (if you've entered the password). I can put a package on your system and show that RHAT could put a modified gpg that logs all your shit and passwords and everything to their server. And so on.
This isn't a vulnerability. It's like saying it's conceptually possible for a thief to steal your car after you've put the key in the ignition.
Support my political activism on Patreon.
yeah something you run on your browser.. ..that gives you access to the files.. CAN GIVE YOU ACCESS TO THE FILES.
wow what a shock! because in this case, MEGA can alter the js so that they get the keys. how this is is news I don't really get. it's just common sense.
the real question is, are there 3rd party mega clients that are not javascript or subject to changing without notice..
What is common sense to anyone who understands how a service is built is not necessarily common sense to those who use it.
So it matters.