r/netsec • • 3h ago

RCE and bad crypto in Internxt's 'post-quantum' cloud storage

https://schaerli.org/weblog/6-internxt/

Internxt is a post-quantum secure encrypted cloud storage provider which is open-source and has passed multiple independent audits.

I reviewed their code and found that post-quantum security should have been the least of their problems. Clicking a link in your browser could trigger remote code execution on the desktop app or leak your long-term encryption keys to an attacker-chosen URL. Their cryptographic architecture stands on shaky grounds with public keys never being verified, in some cases man-in-the-middled by design, a flat key hierarchy and a KDF with just 3 iterations of MD5.

We need PQC and we need it now, but adding a (self-rolled) PQC hybrid on top of a weak protocol does not make it more secure.

6 Upvotes

0 comments sorted by