Missing Context Binding Enables Insider Message Replays in Group Chats
Microsoft Research’s Akshaya Kumar argues that group messaging protocols need to analyze chat encryption separately from group key agreement: a shared group key can protect secrecy while still allowing an insider to reuse another member’s valid signature and impersonate them. Her team’s formal analysis found replay and reordering attacks in MLS and replay weaknesses in Session, tracing them to signatures that were not fully bound to the encryption context, including message generation and nonce.
Microsoft Research·Aug 27, 2026·10 min read