Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There was a deadly security flaw two years ago, that required a protocol breaking fix (done within a week I believe):

https://redrocket.club/posts/croc/

But audits finding vulnerabilities are better than no audit and no known flaw.

Do these tools have iOS apps?




Perhaps you missed this https://news.ycombinator.com/item?id=37608110 but it has given me fresh, sceptical, eyes with which to read cve reports.


Yes, I subscribe to Daniel Stenberg's RSS feed and have seen his many articles bemoaning excessive classification of bugs as vulnerabilities. One of these bugs, however, show serious cryptographic deficiencies. Unfortunately there are a lot of cryptography amateurs making stuff without a proper understanding ond making grandiose claims, so my default stance is one of skepticism unless reputable cryptographers have looked at it.

I use wormhole-william, the Go version of the Python magic wormhole, and age, mostly because of this Latacora endorsement:

https://www.latacora.com/blog/2019/07/16/the-pgp-problem/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: