5 ms·
In case anybody still wonders, I guess realducksoft (the poster of this thread) is the DuckSoft on GitHub, who discovered this problem with help from another Gi
by nirui 6y ago
In case anybody still wonders, I guess realducksoft (the poster of this thread) is the DuckSoft on GitHub, who discovered this problem with help from another GitHub user studentmain.
They are both developers from China, which is why their English isn't very good (My English is bad too, sorry). However, based on my observation, they've spend years on the related field (Let's just call it "Secured Data Transmission"), that makes them the pros here.
So personally, I trust their discovery and believe what they have found is indeed a critical security vulnerability that could threatens people's safety, especially when the service/program was designed to put a middle finger in their government's face. I hope Signal can make something better than this (, and it seems they are trying [0]).
[0] https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuecomment-774982590 https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec...
Off topic: There are only 2 useful posts in the issue #15, one was the #issue-568737654 and another was #issuecomment-774982590, the others were mostly spams. I don't think it helped the situation isn't it?
Oh, by the way, I encountered studentmain once. He was the one who "recovered" the few comments that I replied to an issue under Shadowsocks's GitHub repository from the his email record. The word "recovered" is because I intentionally deleted those comments to protect myself from been exposed too much, and he just pasted everything back on including my name and ask me "why so careful". So he cares about the Privacy of the others now? Well, kudos to him ;)