Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was really hoping Nadim would be successful with CryptoCat, but at least in my eyes, this bug is the failure of the project — especially because his response is, "Cryptocat is not any different from any of the other notable privacy, encryption and security projects, in which vulnerabilities get pointed out on a regular basis and are fixed. Bugs will continue to happen in Cryptocat, and they will continue to happen in other projects as well. This is how open source security works." <http://blog.crypto.cat/2013/07/new-critical-vulnerability-in...

No. This is how open-source "security" fails. GnuPG has not had a security bug since 2008, and I don't think it's ever had a security bug that left your encrypted messages open to interception. You can't start with insecure cryptographic software and bugfix it until it's secure. You'll just bugfix it until only the bad guys know where the new holes are. How long has the Russian equivalent of the NSA (or, if you're Russian, the NSA) known about Lucky Thirteen, for example? How long did they know about the Million Message Attack?

(That, and the array of "15-bit" single-digit integers.)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: