Search Mailing List Archives
alec.muffett at gmail.com
Tue Oct 23 17:04:14 PDT 2012
Maybe someone ought to tell lifehacker this perspective, until Sam gets a
team together to fix it?
On 23 October 2012 20:11, Steve Weis <steveweis at gmail.com> wrote:
> Seconded. Do not use this extension in production.
> I briefly looked at the code and found some mistakes: unauthenticated
> encryption, use of ECB for larger than one block, use of 512-bit ElGamal
> keys, possible timing attack to recover secret key hash, possible entropy
> exhaustion DoS attack, etc.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the liberationtech