Radicle: Disclosure of Vulnerability in the Network Protocol
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Radicle: Disclosure of Vulnerability in the Network Protocol
Unofficial Hacker News client; not affiliated with Y Combinator.
Aurornis · · focus · HN ↗
> Network traffic between nodes is not encrypted and not authenticated.
Oh.
After all of the work they put into using cryptographic identities and decentralization tricks, how did they forget to do anything about the network traffic?
Was this a case of thinking they'd handle it later, but then it fell off the TODO list?
dkmb · · focus · HN ↗
Which I can understand to an extent with large, high-traffic dependencies but these were really low traffic projects with like 10 stars on github and barely any development... Well, hindsight is 20/20.
Aurornis · · focus · HN ↗
It's unfortunate that write-up is AI generated ("Here's the catch... And this is the part that honestly surprised me" tipped me off, and Pangram cites it as 100% AI too), because it's hard to understand what's happening.
It looks like the Noise API can be confusing. They tried to implement it, got the handshake and key exchange right, but then used Noise API calls intended for sending raw data directly to the wire without the encryption they set up? So keys were exchanged, then never used?
gsaslis · · focus · HN ↗
I believe the blog post being referred to here is the one linked to in the title (i.e. <a href="https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol" rel="nofollow">https://radicle.dev/2026/09/23/disclosure-of-vulnerability-i...)
dkmb · · focus · HN ↗