Radicle: Disclosure of Vulnerability in the Network Protocol
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Radicle: Disclosure of Vulnerability in the Network Protocol
Unofficial Hacker News client; not affiliated with Y Combinator.
john_strinlai · · focus · HN ↗
announcement 3 months later is not super great, considering that the current advice is "Stop using private repositories (over the network) until the security update is released."
vocx2tx · · focus · HN ↗
FAQ still says that "Radicle supports private repositories [...] completely invisible to the rest of the network" [1]
[0] <a href="https://radicle.dev/guides/user#initializing-a-private-repository" rel="nofollow">https://radicle.dev/guides/user#initializing-a-private-repos...
[1] <a href="https://radicle.dev/faq" rel="nofollow">https://radicle.dev/faq
gsaslis · · focus · HN ↗
Eduard · · focus · HN ↗
"Transport Encryption & Privacy: Connections between peers in the Radicle network are encrypted using a Noise protocol handshake. [...] After the handshake phase is completed, all data exchanged between peers is fully encrypted and benefits from strong forward secrecy, ensuring secure and private communications across the network."
conartist6 · · focus · HN ↗
Me: "No!"
gsaslis · · focus · HN ↗