Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AES key should be encrypted before exchange #378

Open
muke1908 opened this issue Sep 19, 2024 · 0 comments
Open

AES key should be encrypted before exchange #378

muke1908 opened this issue Sep 19, 2024 · 0 comments
Labels
Backend bug Something isn't working medium Pull request is medium

Comments

@muke1908
Copy link
Owner

await sharePublicKey({ aesKey: aesPlain, publicKey: this.publicKey, sender: this.userId, channelId: this.channelId});

Right now AES encryption key is sent to server for exchange which is a vulnerability. It should be send via end-to-end encrypted channel.

@muke1908 muke1908 added bug Something isn't working medium Pull request is medium Backend labels Sep 19, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Backend bug Something isn't working medium Pull request is medium
Projects
None yet
Development

No branches or pull requests

1 participant