‹ BackHN Continuity

Thread

Radicle: Disclosure of Vulnerability in the Network Protocol

154 points · 58 comments · lostmsu

  1. Tiberium · · focus · HN ↗
    I honestly thought there would be some elaborate chain there, not "we forgot to use encryption"...
    1. pixl97 · · focus · HN ↗
      Honestly issues like this crop up pretty commonly. JWT alg:none for example. Or even older people forcing SSL to downgrade to encryption null.

      In any system that provides security it should only be designed to run if the security is in use, and to fail immediately with no further action if the security is not used.

      1. [deleted] · · focus · HN ↗

        [deleted]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.