
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
securityvulnerabilityRCEcryptographycloud storagepost-quantumInternxtencryptionremote code execution
A security researcher reviewed Internxt's code, an open-source post-quantum encrypted cloud storage provider, and discovered multiple critical vulnerabilities. The findings include remote code execution triggered by clicking a link in a browser, potential leakage of long-term encryption keys to attacker-controlled URLs, unverified public keys, man-in-the-middle vulnerabilities by design, a flat key hierarchy, and a key derivation function using only 3 iterations of MD5. The researcher states that Internxt added a self-rolled post-quantum cryptography hybrid on top of a weak protocol.