3 ms·
He went a really long way since 2013 and his debuts with CryptoCat : he got a PhD in one of the top European crypto research team, on formal verification of cry
by Harvesterify 6y ago
He went a really long way since 2013 and his debuts with CryptoCat : he got a PhD in one of the top European crypto research team, on formal verification of crypto implementations.
I would confidently guess that's way more legitimate that any opinion you could formulate against this audit, based on ad hominem attacks.
- brohee 6y agoHe completely rewrote CryptoCat in 2016 and that still wasn't good, the security page was at https://web.archive.org/web/20160407125207/https://crypto.cat/security.html https://web.archive.org/web/20160407125207/https://crypto.ca... and there were still pretty bad issues, notably the file sharing disclosing the exact size of the file shared, despite him stating "Cryptocat makes the following assumptions: Untrusted network: We assume that an attacker controls the network and so can intercept, tamper with and inject network messages.". This was not "ECDH completely broken" bad, by far, but still far from good. I guess that was still before obtaining his PhD. And about not liking the guy, I'll admit reading https://www.courtlistener.com/docket/14868600/todd-v-reichwein/ https://www.courtlistener.com/docket/14868600/todd-v-reichwe... biased me...