Paper 2026/1994
Data-strophy: When Your Integrity Goes Wild, So Does Your Data!
Abstract
Proton is a popular security and privacy service provider with a large user base spanning both organizations and individuals. Proton Docs/Sheets support real-time collaborative document editing while claiming to provide end-to-end security. We analyze the cryptographic design and the collaborative editing protocol of Proton Docs/Sheets inspecting the open-source Web client and webpage code. We demonstrate three distinct ``integrity'' attacks against Proton Docs/Sheets that can cause history rewriting, context manipulation, and censorship, all of which can, in fact, evade detection. The first two can be launched even when the Proton server acts honestly, and the third is mounted by a corrupted Proton server. We also present the corresponding mitigation methods. Our attacks highlight the subtleties of end-to-end security in collaborative settings involving multiple users and constant updates. This state of affairs naturally calls for systematic formal treatment (i.e., design and/or analysis) of the security of such systems.
Metadata
- Available format(s)
-
PDF
- Category
- Attacks and cryptanalysis
- Publication info
- Published elsewhere. Minor revision. ACM CCS 2026
- DOI
- 10.1145/3830454.3846605
- Keywords
- Cryptographic AttacksE2EE
- Contact author(s)
-
yanan li @ sydney edu au
yaqings @ 163 com
qiang tang @ sydney edu au
moti @ google com
zhangyuan @ uestc edu cn - History
- 2026-09-14: revised
- 2026-09-12: received
- See all versions
- Short URL
- https://ia.cr/2026/1994
- License
-
CC BY-NC-ND
BibTeX
@misc{cryptoeprint:2026/1994,
author = {Ya-Nan Li and Yaqing Song and Qiang Tang and Moti Yung and Yuan Zhang},
title = {Data-strophy: When Your Integrity Goes Wild, So Does Your Data!},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1994},
year = {2026},
doi = {10.1145/3830454.3846605},
url = {https://eprint.iacr.org/2026/1994}
}