hypnosec writes that software developer Michael Koziarski has released a bookmarklet “which he claims has the ability to reveal Mega users’ master key. Koziarski went on to claim that Mega has the ability to grab its users’ keys and use them to access their files. Dubbed MegaPWN, the tool not only reveals a user’s master key, but also gives away a user’s RSA private key exponent. ‘MEGApwn is a bookmarklet that runs in your web browser and displays your supposedly secret MEGA master key, showing that it is not actually encrypted and can be retrieved by MEGA or anyone else with access to your computer without you knowing,’ reads an explanation about the bookmarklet on its official page.”… hypnosec writes that software developer Michael Koziarski has released a bookmarklet “which he claims has the ability to reveal Mega users’ master key. Koziarski went on to claim that Mega has the ability to grab its users’ keys and use them to access their files. Dubbed MegaPWN, the tool not only reveals a user’s master key, but also gives away a user’s RSA private key exponent. ‘MEGApwn is a bookmarklet that runs in your web browser and displays your supposedly secret MEGA master key, showing that it is not actually encrypted and can be retrieved by MEGA or anyone else with access to your computer without you knowing,’ reads an explanation about the bookmarklet on its official page.”

Read more of this story at Slashdot.






Read more http://rss.slashdot.org/~r/Slashdot/slashdot/~3/Z3hKgu1X2UY/story01.htm