4 ms·
croc probably shouldn't be used if you want security: [1] https://news.ycombinator.com/item?id=27054885 https://news.ycombinator.com/item?id=27054885 [2] http
by throwaway67114 5y ago
croc probably shouldn't be used if you want security:
[1] https://news.ycombinator.com/item?id=27054885 https://news.ycombinator.com/item?id=27054885
[2] https://twitter.com/Sc00bzT/status/1396199915638992896 https://twitter.com/Sc00bzT/status/1396199915638992896
Magic Wormhole has a good implementation in Go, which is compatible with the original Python implementation (croc is not compatible with magic wormhole). It has windows binary and binaries for most of the popular OS.
https://github.com/psanford/wormhole-william https://github.com/psanford/wormhole-william
Binaries: https://github.com/psanford/wormhole-william/releases https://github.com/psanford/wormhole-william/releases
There's GUI: https://github.com/Jacalz/wormhole-gui https://github.com/Jacalz/wormhole-gui
Android app too: https://github.com/psanford/wormhole-william-mobile https://github.com/psanford/wormhole-william-mobile
Support for resuming transfers is planned I think.
- tobias2014 5y agoIn a sense it is good when people actually check opensource software for security vulnerabilities, and these get fixed, no? There would only be reason of concern if a project shows overall continued sloppiness, but I'm not aware of that for croc. Correct me if I'm wrong.
- exadeci 5y agoThey seem to be sloppy: >The only thing I know about croc is that they misread a SPAKE2 description and it was very broken (https://github.com/schollz/pake/commit/04729caa1862a96ce3aef043c315d87ab92c360f#diff-3392294668649ee2b185383421a6b8e31ad9bac0662f6cf39629345ca064e65aL121-R125 https://github.com/schollz/pake/commit/04729caa1862a96ce3aef...) while also not knowing how long private keys should be