Ukukhishwa kweklayenti le-Riot Matrix 1.6 ngokubethela ngasemaphethelweni kunikwe amandla

Abathuthukisi bohlelo lwezokuxhumana oluhlukaniselwe iMatrix kwethulwe ukukhishwa okusha kwezicelo ezibalulekile zeklayenti I-Riot Web 1.6, i-Riot Desktop 1.6, i-Riot iOS 0.11.1 ne-RiotX Android 0.19. I-Riot ibhalwa kusetshenziswa ubuchwepheshe bewebhu kanye nohlaka lwe-React (isibopho siyasetshenziswa I-React Matrix SDK). Inguqulo yedeskithophu uya ku ngokusekelwe endaweni yesikhulumi se-Electron. Ikhodi isatshalaliswa ngu ilayisensi ngaphansi kwe-Apache 2.0.

Ukhiye ngcono ezinguqulweni ezintsha, ukubethela kokuphela ukuya ekupheleni (E2EE, ukubethela kokuphela ukuya ekupheleni) kunikwe amandla ngokuzenzakalela kuzo zonke izingxoxo eziyimfihlo ezintsha, ezifakwa ngokuthumela izimemo. Ukubethela ngasemaphethelweni kusetshenziswa ngokususelwe kuphrothokholi yayo, esebenzisa i-algorithm yokushintshanisa ukhiye kwasekuqaleni kanye nokugcinwa kokhiye beseshini. i-ratchet kabili (ingxenye yephrothokholi Yesiginali).

Ukuze uxoxisane ngokhiye ezingxoxweni nabahlanganyeli abaningi, sebenzisa isandiso I-Megolm, elungiselelwe ukubethela imilayezo enenani elikhulu labamukeli futhi ivumela umlayezo owodwa ukuthi ususwe ukubethela izikhathi eziningi. Umbhalo we-ciphertext ungagcinwa kuseva engathenjwa, kodwa awukwazi ukususwa ukubethela ngaphandle kokhiye beseshini abagcinwe ohlangothini lweklayenti (iklayenti ngalinye linokhiye walo wesikhathi). Lapho ubhala ngekhodi, umlayezo ngamunye ukhiqizwa ngokhiye wawo ngokusekelwe kukhiye wesikhathi seklayenti, oqinisekisa umlayezo ngokuhlobene nombhali. Ukunqamula ukhiye kukuvumela ukuthi uphazamise kuphela imilayezo esivele ithunyelwe, kodwa hhayi imilayezo ezothunyelwa esikhathini esizayo. Ukuqaliswa kwezindlela zokubethela kwacwaningwa yi-NCC Group.

Ushintsho lwesibili olubalulekile ukwenza kusebenze ukusekela kokusayina okuphambene, okuvumela umsebenzisi ukuthi aqinisekise iseshini entsha kusukela kuseshini esivele iqinisekisiwe. Ngaphambilini, lapho kuxhunywa engxoxweni yomsebenzisi kusuka kudivayisi entsha, isexwayiso saboniswa kwabanye ababambi qhaza ukugwema ukulalela uma umhlaseli efinyelele i-akhawunti yesisulu. Ukuqinisekisa okuphambene kuvumela umsebenzisi ukuthi aqinisekise amanye amadivayisi akhe lapho engena ngemvume futhi aqinisekise ukwethemba ukungena ngemvume okusha noma anqume ukuthi othile uzame ukuxhuma ngaphandle kolwazi lwakhe.

Ukwenza lula ukusethwa kokungena okusha, amandla okusebenzisa amakhodi e-QR anikeziwe. Izicelo zokuqinisekisa nemiphumela manje zilondolozwe emlandweni njengemilayezo ethunyelwe ngokuqondile. Esikhundleni sengxoxo yemodi ye-pop-up, ukuqinisekiswa manje kwenziwa kubha eseceleni. Phakathi kwamathuba ahambisanayo, ungqimba luyaphawulwa I-Pantalaimon, okukuvumela ukuthi uxhume ezingxoxweni ezibethelwe ezivela kumakhasimende angasekeli i-E2EE, futhi isebenza ngasohlangothini lweklayenti indlela sesha futhi ukhombe amafayela ezindlini zokuxoxa ezibethelwe.

Ukukhishwa kweklayenti le-Riot Matrix 1.6 ngokubethela ngasemaphethelweni kunikwe amandla

Masikhumbule ukuthi inkundla yokuhlela i-Matrix yezokuxhumana emisiwe ithuthuka njengephrojekthi esebenzisa amazinga avulekile futhi inaka kakhulu ekuqinisekiseni ukuphepha nobumfihlo babasebenzisi. Okokuthutha okusetshenzisiwe yi-HTTPS+JSON okungenzeka usebenzise i-WebSockets noma iphrothokholi esekelwe kuyo I-COAP+Noise. Uhlelo lwakhiwe njengomphakathi wamaseva angakwazi ukusebenzisana namanye futhi ahlanganiswe abe inethiwekhi efanayo ehlukaniselwe izindawo. Imilayezo iphindaphindwa kuwo wonke amaseva lapho abahlanganyeli bemilayezo baxhumeke khona. Imilayezo isatshalaliswa kuwo wonke amaseva ngendlela efanayo naleyo eyenziwa ngayo isakazwa phakathi kwamakhosombe e-Git. Esimeni lapho iseva inqamuka, imilayezo ayilahleki, kodwa idluliselwa kubasebenzisi ngemva kokuba iseva iqale ukusebenza. Izinketho ezihlukahlukene ze-ID yomsebenzisi ziyasekelwa, okuhlanganisa i-imeyili, inombolo yocingo, i-akhawunti ye-Facebook, njll.

Ukukhishwa kweklayenti le-Riot Matrix 1.6 ngokubethela ngasemaphethelweni kunikwe amandla

Alikho iphuzu elilodwa lokwehluleka noma ukulawula umlayezo kuyo yonke inethiwekhi. Wonke amaseva ahlanganiswe engxoxweni ayalingana namanye.
Noma yimuphi umsebenzisi angasebenzisa iseva yakhe futhi ayixhume kunethiwekhi evamile. Kungenzeka ukudala amasango ngokusebenzisana kwe-Matrix nezinhlelo ezisuselwe kwezinye izivumelwano, isibonelo, ilungisiwe izinsiza zokuthumela imiyalezo ngezindlela ezimbili ku-IRC, Facebook, Telegraph, Skype, Hangouts, Email, WhatsApp kanye ne-Slack.

Ngaphezu kokuthumela imiyalezo esheshayo nezingxoxo, uhlelo lungasetshenziswa ukudlulisa amafayela, ukuthumela izaziso,
ukuhlela ama-teleconferences, ukwenza izingcingo zezwi nezevidiyo.
I-Matrix ikuvumela ukuthi usebenzise ukusesha nokubuka okungenamkhawulo komlando wezincwadi. Iphinde isekele izici ezithuthukile njengesaziso sokuthayipha, ukuhlolwa kokuba khona komsebenzisi ku-inthanethi, ukuqinisekiswa kokufunda, izaziso zohlelo lokusebenza, ukusesha ohlangothini lweseva, ukuvumelanisa umlando kanye nesimo seklayenti.

Source: opennet.ru

Engeza amazwana