jsgf ([personal profile] jsgf) wrote in [personal profile] mjg59 2020-07-28 01:31 am (UTC)

Tahoe LAFS information confirmation attack

This came up in Tahoe's use of convergent encryption which allows you do confirm some missing information. For example, if you know someone has a PDF template of a form which you know everything about except an SSN field, you can generate forms with all the SSNs and look for collisions, thereby confirming their SSN.

In this case, you could perform the same attack but look for dedups.


Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org