Practically-exploitable Cryptographic Vulnerabilities in Matrix

Sofía Celi (Brave Software), Martin R. Albrecht (King's College London), Benjamin Dowling (University of Sheffield), Daniel Jones (Royal Holloway, University of London) | Security, Cryptography

We report several practically-exploitable cryptographic vulnerabilities in the Matrix standard for federated real-time communication and its flagship client and prototype implementation, Element. These, together, invalidate the confidentiality and authentication guarantees claimed by Matrix against a malicious server. This is despite Matrix’ cryptographic routines being constructed from well-known and -studied cryptographic building blocks. The vulnerabilities we exploit differ in their nature (insecure by design, protocol confusion, lack of domain separation, implementation bugs) and are distributed broadly across the different subprotocols and libraries that make up the cryptographic core of Matrix and Element. Together, these vulnerabilities highlight the need for a systematic and formal analysis of the cryptography in the Matrix standard.

View paper

Links

Ready for a better Internet?

Brave’s easy-to-use browser blocks ads by default, making the Web faster, safer, and less cluttered for people all over the world.

Brave logo

Almost there…

Please continue the installation of Brave in the .

Google Play app .

You’re just 60 seconds away from the best privacy online

  1. Download Brave
  2. Run the installer
  3. Import settings
  1. step 1
    Download Brave

    Open the installer from Chrome's downloads (it should be in the upper right corner of this window).

  2. step 2
    Run the installer

    If you're prompted to, click “Yes” in the User Access Control dialog.

  3. step 3
    Import settings

    Wait for the installation to finish, then import your browser settings from Chrome.

If your download didn’t start automatically, click .

Need help?