3 ms·
IIRC, it was a nonce-not-used-only-once vulnerability, wasn't it? Wouldn't that be tricky to detect, even in Rust? Regardless, it's quite unfortunate to see Co
by mkfs 1y ago
IIRC, it was a nonce-not-used-only-once vulnerability, wasn't it? Wouldn't that be tricky to detect, even in Rust?
Regardless, it's quite unfortunate to see Colin's nits picked in this manner, dredging up some mistake from almost 15 years ago (which he handled as responsibly as could be expected), given all of the work he's done on FreeBSD and for giving the world scrypt.
- cperciva 1y agogiving the world scrypt Ironically that bug happened because of scrypt. Creating scrypt led me to refactor Tarsnap's crypto code, which is when the bug slipped in.