Linchakin

Critical Flaws in MEGA Cloud Storage Let Attacker Decrypt User Data

 June 23, 2022     No comments   

Critical Flaws MEGA Cloud Storage

The experts at one of Europe’s leading universities, ETH Zurich, Switzerland reported a critical vulnerability in MEGA cloud storage that allows the attacker to decrypt the user data.

MEGA is a cloud storage and file hosting service offered by MEGA Limited, a company based in Auckland, New Zealand. The service is offered through web-based apps. MEGA mobile apps are also available for Android and iOS.  The company is known for the largest fully featured free cloud storage in the world with 20 GB storage allocation for free accounts.

MEGA has released software updates that fix a critical vulnerability that exposes user data.

How the Attack is carried out?

EHA

The researchers say an attacker would have gained control over the heart of MEGA’s server infrastructure or achieved a successful man-in-the-middle attack on the user’s TLS connection to MEGA.

When a targeted account had made enough successful logins, incoming shared folders, MEGAdrop files, and chats could have been decryptable. Files in the cloud drive could have been successively decrypted during subsequent logins. In addition, files could have been placed in the account that appears to have been uploaded by the account holder (a “framing” attack).

A team of researchers from the Applied Cryptography Group at the Department of Computer Science, ETH Zurich, reported a total of five vulnerabilities in MEGA’s cryptographic architecture.

Five Attacks Identified by the Researchers

The Identified Vulnerabilities

  • Incrementally accumulate some information every time a MEGA user logs in.
  • After a minimum of 512 such logins, the collected information enabled the attacker to decrypt parts of the account and also leverage further logins to successively decrypt the remainder of it.
  • Privacy and integrity of all stored data and chats are being destroyed.
  • Insert arbitrary files into a user’s account.
  • The issue is in the legacy chat key exchange mechanism.

Researchers noted that even if a provider’s API servers become controlled by an adversary, the encrypted user data should never be readable by the attacker – not even after 512 logins.

Furthermore, the folder links are not integrity-protected and carry the required meta AES key, and the mechanics underpinning the MEGAdrop feature could be leveraged.

Updates Available

Users are recommended to upgrade the client software on all devices and then convert their account to a new, backward-incompatible, format.

“We urge all users who are logging in frequently to upgrade their MEGA app as soon as possible. We also invite vendors of third-party client software to upgrade to the latest MEGA SDK, and those who maintain their own MEGA API client implementation, to add an equivalent fix.”, according to the security update released by MEGA.

MEGA has fixed the two vulnerabilities that can lead to user data decryption on all clients – RSA key recovery and plaintext recovery, mitigated the third one – framing, and in the future, the company will address the remaining two issues.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • Intel's Core i9-12900K Just Hit 8 GHz Along With DDR5-8300ByZhiye Liu 03 November 2021Famous extreme overclocker HiCookie overclocks the Core i9-12900...Overclocking maestro HiCookie (courtesy of Aorus Spain's Twitter) has overclocked Intel's flagship Core i9-12900K Alder Lake to an impressive 8 GHz wi… Read More
  • IBM Introduces CLOPS Performance Standard for Quantum ComputingByFrancisco Pires 03 November 2021Short for Circuit Layer Operations per SecondIBM has risen to the challenge of creating a new performance standard for quantum computing. The new metric focuses on Circuit Layer Operations per Se… Read More
  • 8 Truth Bombs of Launching your Product on Product Hunt🚀 November 3rd 2021 new story Wylo, an interest-based social network on Product Hunt, launched last month. We managed to secure … Read More
  • How to Not Be a Victim to the Catfishing Pandemic Spike[unable to retrieve full-text content] You may be interested in: >> Is a Chromebook worth replacing a Windows laptop? >> Find out in deta… Read More
  • Intel May Be Readying up to 32 Arc Alchemist GPU ModelsByAnton Shilov 03 November 2021Intel's new GPU drivers imply on the number of DG2 SKUs. According to a new driver release, Intel may be prepping as many as 32 Arc Alchemist discrete GPU models for desktops and laptops. The numb… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates