4 ms·
https://github.com/privacytools/privacytools.io/issues/566 https://github.com/privacytools/privacytools.io/issues/566
by oehtXRwMkIs 5y ago
https://github.com/privacytools/privacytools.io/issues/566 https://github.com/privacytools/privacytools.io/issues/566
- bovermyer 5y agoWhile a mildly interesting discussion, it does not appear to have any merit with regards to Tox itself.
- hannob 5y agoIt links to a bug report discussion where one of the developers states that they don't understand the security properties of tox very well[1]. I find that worrying. [1] https://github.com/TokTok/c-toxcore/issues/426 https://github.com/TokTok/c-toxcore/issues/426
- GoblinSlayer 5y agoIsn't it the reason why you do audits?
- grayhatter 5y agolol, I think you're probably talking about me. I remember that troll, he's what killed a lot of my motivation to work on Tox too. He likes stiring up shit on other foss projects too :/. Saying I don't understand the security properties is an interesting take. My intended comments meant I misunderstood the issue. I was only half paying attention at the time; I assumed it was another troll reposting the same issue "if someone steals your private keys they can steal your identity". Which is true, but an annoying complaint, because that's how crypto has to work. To be sure, I didn't write base the protocol itself, nor the crypto primitives. So while I don't agree with the assertion, even if it was true. It wouldn't matter because I didn't design the original system :)
- ueueshitashita 5y ago>I remember that troll Made me chuckle that you're referring to Jason Donenfeld as "that troll"
- aasasd 5y agoThere was also the time when an issue was created to ask for an independent audit, and the authors couldn't comprehend why an audit would be needed. (If I remember things right.) Edit: here's the discussion, from seven years ago. The authors aren't particularly opposed to an audit, but keep saying “Tox is secure, we use Nacl”.
- grayhatter 5y agoYou're not remembering things correctly. The core dev team, and everyone helping with the project all agreed the whole project. Meaning the system, the protocol, and the code. Should all be audited by an independent security group. The issue we had, was the price tag of such a service. Every dev wanted a full audit, we just simply couldn't afford it. Separately, why do I get the impression you're trying to spread FUD about tox? All your comments seem to be negative and misstated :(