Technical community questions protocol design and testing practices
3 Today 12:41 PM · 10h ago · 3 comments · 1 source · development 3 of 4
Developers and security professionals expressed alarm at the fundamental nature of the flaw—an entire protocol lacking encryption despite using Noise. Comments focused on the absence of basic verification like packet inspection (Wireshark) and questioned how this escaped testing for 3+ years.
“No offense, but how can you build a protocol that accidentally does not encrypt stuff at all? Don't you at some point look at the wires?”
freddybRadicle Decentralized git hosting platformKonstantinos Maninakis Security researcher
The whole story articlespostscomments the bright band is this development · numbered dots are the others · click one to jump
What people said 3 voices · verbatim
-
No offense, but how can you build a protocol that accidentally does not encrypt stuff at all? Don't you at some point look at the wires? Re-implement the protocol as a different clients - for tests?
-
Yeah, I think your tone is entirely valid. I've poked at Radicle in the past, and I love what it in theory is doing, but it...I dunno how to put this, but after being in the industry for so long, you kind of get a feel for something being *off* in a project? I'd have a hell of a time articulating what I was noticing, but it was enough I stopped…
-
> We recommend to stop using private repositories until a fix is released. This seems like death; I'm not sure how they can recover from this.
All 4 developments of Radicle discloses critical network protocol vulnerabilities… →
LobstersHacker NewsNewswiresMastodon