r/netsec • • 1d ago

RCE and bad crypto in Internxt's 'post-quantum' cloud storage

https://schaerli.org/weblog/6-internxt/

Internxt is a post-quantum secure encrypted cloud storage provider which is open-source and has passed multiple independent audits.

I reviewed their code and found that post-quantum security should have been the least of their problems. Clicking a link in your browser could trigger remote code execution on the desktop app or leak your long-term encryption keys to an attacker-chosen URL. Their cryptographic architecture stands on shaky grounds with public keys never being verified, in some cases man-in-the-middled by design, a flat key hierarchy and a KDF with just 3 iterations of MD5.

We need PQC and we need it now, but adding a (self-rolled) PQC hybrid on top of a weak protocol does not make it more secure.

27 Upvotes

3 comments sorted by

2

u/DamnFog 23h ago

Really interesting write up, thank you for posting! It feels like it has been a while since I've read one that didn't read like slop.

1

u/pascalschaerli 20h ago

Thanks, means a lot! I do use LLMs a lot but for this type of writing I dind't manage to get good results yet, so I end up re-writing most of it manually.