{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2018:24MQEQ62XB2X67AF2A2QAMEZTX","short_pith_number":"pith:24MQEQ62","canonical_record":{"source":{"id":"1802.03367","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-09T18:02:22Z","cross_cats_sorted":[],"title_canon_sha256":"1b3909437204ad31f862e91d105e1edcd5a820d4186f26589ef8c8d0f85175dc","abstract_canon_sha256":"76f201a4faea8a2fd974ebdde42d31f2850ecb0ddcd681678d017d00380be06c"},"schema_version":"1.0"},"canonical_sha256":"d7190243dab8757f7c05d0350030999dd97918b579c9bcfde453b3c86bac1624","source":{"kind":"arxiv","id":"1802.03367","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.03367","created_at":"2026-05-18T00:23:57Z"},{"alias_kind":"arxiv_version","alias_value":"1802.03367v1","created_at":"2026-05-18T00:23:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.03367","created_at":"2026-05-18T00:23:57Z"},{"alias_kind":"pith_short_12","alias_value":"24MQEQ62XB2X","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"24MQEQ62XB2X67AF","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"24MQEQ62","created_at":"2026-05-18T12:31:59Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2018:24MQEQ62XB2X67AF2A2QAMEZTX","target":"record","payload":{"canonical_record":{"source":{"id":"1802.03367","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-09T18:02:22Z","cross_cats_sorted":[],"title_canon_sha256":"1b3909437204ad31f862e91d105e1edcd5a820d4186f26589ef8c8d0f85175dc","abstract_canon_sha256":"76f201a4faea8a2fd974ebdde42d31f2850ecb0ddcd681678d017d00380be06c"},"schema_version":"1.0"},"canonical_sha256":"d7190243dab8757f7c05d0350030999dd97918b579c9bcfde453b3c86bac1624","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:23:57.810135Z","signature_b64":"xEnyEiYLZ7tcnLuspYoOtDWAKK6XH4h3YteenyR3NxJ4GLPwHEcqxKLTtzn8+FFcEqPIwyKibson/Mw996ohDA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d7190243dab8757f7c05d0350030999dd97918b579c9bcfde453b3c86bac1624","last_reissued_at":"2026-05-18T00:23:57.809505Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:23:57.809505Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1802.03367","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:23:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"xZUlI3Ic1z4h6tPr0zQsSPtG46tOZdVsFxu03byxU1GA2DYspDyI2rgsR+o55feEyZFb4P1ZEru78KUZ7ISjBA==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T14:32:04.561758Z"},"content_sha256":"32ada74388665eedbafd2fe20001f64fe360feefa42275ad79fe3b7ae81db7e9","schema_version":"1.0","event_id":"sha256:32ada74388665eedbafd2fe20001f64fe360feefa42275ad79fe3b7ae81db7e9"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2018:24MQEQ62XB2X67AF2A2QAMEZTX","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"When Textbook RSA is Used to Protect the Privacy of Hundreds of Millions of Users","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Jedidiah Crandall, Jeffrey Knockel, Thomas Ristenpart","submitted_at":"2018-02-09T18:02:22Z","abstract_excerpt":"We evaluate Tencent's QQ Browser, a popular mobile browser in China with hundreds of millions of users---including 16 million overseas, with respect to the threat model of a man-in-the-middle attacker with state actor capabilities. This is motivated by information in the Snowden revelations suggesting that another Chinese mobile browser, UC Browser, was being used to track users by Western nation-state adversaries.\n  Among the many issues we found in QQ Browser that are presented in this paper, the use of \"textbook RSA\"---that is, RSA implemented as shown in textbooks, with no padding---is par"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.03367","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-05-18T00:23:57Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"ZWIGQg7bV1P0Z5bcSpeAShpoN82igCCwoPtzjdZ6rE9Dg9sQliQetvpomhQoK0CGtIGWYT0tWhWl4A32+6X+DQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-06-07T14:32:04.562430Z"},"content_sha256":"849a4cbb218f0473615dfffb4eb7b7ab43d73217f8efff6f8beb302f8efcab9c","schema_version":"1.0","event_id":"sha256:849a4cbb218f0473615dfffb4eb7b7ab43d73217f8efff6f8beb302f8efcab9c"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/24MQEQ62XB2X67AF2A2QAMEZTX/bundle.json","state_url":"https://pith.science/pith/24MQEQ62XB2X67AF2A2QAMEZTX/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/24MQEQ62XB2X67AF2A2QAMEZTX/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-06-07T14:32:04Z","links":{"resolver":"https://pith.science/pith/24MQEQ62XB2X67AF2A2QAMEZTX","bundle":"https://pith.science/pith/24MQEQ62XB2X67AF2A2QAMEZTX/bundle.json","state":"https://pith.science/pith/24MQEQ62XB2X67AF2A2QAMEZTX/state.json","well_known_bundle":"https://pith.science/.well-known/pith/24MQEQ62XB2X67AF2A2QAMEZTX/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2018:24MQEQ62XB2X67AF2A2QAMEZTX","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"76f201a4faea8a2fd974ebdde42d31f2850ecb0ddcd681678d017d00380be06c","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-09T18:02:22Z","title_canon_sha256":"1b3909437204ad31f862e91d105e1edcd5a820d4186f26589ef8c8d0f85175dc"},"schema_version":"1.0","source":{"id":"1802.03367","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1802.03367","created_at":"2026-05-18T00:23:57Z"},{"alias_kind":"arxiv_version","alias_value":"1802.03367v1","created_at":"2026-05-18T00:23:57Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.03367","created_at":"2026-05-18T00:23:57Z"},{"alias_kind":"pith_short_12","alias_value":"24MQEQ62XB2X","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_16","alias_value":"24MQEQ62XB2X67AF","created_at":"2026-05-18T12:31:59Z"},{"alias_kind":"pith_short_8","alias_value":"24MQEQ62","created_at":"2026-05-18T12:31:59Z"}],"graph_snapshots":[{"event_id":"sha256:849a4cbb218f0473615dfffb4eb7b7ab43d73217f8efff6f8beb302f8efcab9c","target":"graph","created_at":"2026-05-18T00:23:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"paper":{"abstract_excerpt":"We evaluate Tencent's QQ Browser, a popular mobile browser in China with hundreds of millions of users---including 16 million overseas, with respect to the threat model of a man-in-the-middle attacker with state actor capabilities. This is motivated by information in the Snowden revelations suggesting that another Chinese mobile browser, UC Browser, was being used to track users by Western nation-state adversaries.\n  Among the many issues we found in QQ Browser that are presented in this paper, the use of \"textbook RSA\"---that is, RSA implemented as shown in textbooks, with no padding---is par","authors_text":"Jedidiah Crandall, Jeffrey Knockel, Thomas Ristenpart","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-09T18:02:22Z","title":"When Textbook RSA is Used to Protect the Privacy of Hundreds of Millions of Users"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.03367","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:32ada74388665eedbafd2fe20001f64fe360feefa42275ad79fe3b7ae81db7e9","target":"record","created_at":"2026-05-18T00:23:57Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"76f201a4faea8a2fd974ebdde42d31f2850ecb0ddcd681678d017d00380be06c","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-09T18:02:22Z","title_canon_sha256":"1b3909437204ad31f862e91d105e1edcd5a820d4186f26589ef8c8d0f85175dc"},"schema_version":"1.0","source":{"id":"1802.03367","kind":"arxiv","version":1}},"canonical_sha256":"d7190243dab8757f7c05d0350030999dd97918b579c9bcfde453b3c86bac1624","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"d7190243dab8757f7c05d0350030999dd97918b579c9bcfde453b3c86bac1624","first_computed_at":"2026-05-18T00:23:57.809505Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-05-18T00:23:57.809505Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"xEnyEiYLZ7tcnLuspYoOtDWAKK6XH4h3YteenyR3NxJ4GLPwHEcqxKLTtzn8+FFcEqPIwyKibson/Mw996ohDA==","signature_status":"signed_v1","signed_at":"2026-05-18T00:23:57.810135Z","signed_message":"canonical_sha256_bytes"},"source_id":"1802.03367","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:32ada74388665eedbafd2fe20001f64fe360feefa42275ad79fe3b7ae81db7e9","sha256:849a4cbb218f0473615dfffb4eb7b7ab43d73217f8efff6f8beb302f8efcab9c"],"state_sha256":"aa3fe55b10cdd0a12e0aa1e4d242a4649c73e003c3a68e704195436df6113426"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"hg/QfbUBCmJ6ECkNBOXLZiNEC6MTvGcET2QFnXB1QfKzKFm9KNzKhFUGgQhVnulda9cjNEfTDUFbQo8eMvGqAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-06-07T14:32:04.565942Z","bundle_sha256":"5eca82837ab68860eb22975ec3788fa3e57b0e25942254d6998bd4eb66a705d2"}}