-
Notifications
You must be signed in to change notification settings - Fork 183
client: conform to Security Guidelines #155
Copy link
Copy link
Closed
Labels
area: clienttelegram package issuestelegram package issuesepicFeature that is too big for single issueFeature that is too big for single issuesecuritySecurity-related issuesSecurity-related issues
Description
- Validation of DH parameters
- g_a and g_b validation
- Checking SHA1 hash values during key generation
- Checking nonce, server_nonce and new_nonce fields
- Using secure pseudorandom number generator to create DH secret parameters a and b
- Checking SHA256 hash value of msg_key
- Checking message length
- Checking session_id
- Checking msg_id
- Behavior in case of mismatch (we are ignoring message, but don't perform full re-connection)
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area: clienttelegram package issuestelegram package issuesepicFeature that is too big for single issueFeature that is too big for single issuesecuritySecurity-related issuesSecurity-related issues