Cryspen’s co-founder Karthikeyan Bhargavan told The Register last week: we did not do great with these advisories. You can say that again. Nadim Kobeissi, an applied cryptographer, found thirteen vulnerabilities in Cryspen’s libcrux and hpke-rs libraries. He published the findings in an IACR ePrint paper titled “Verification Theatre.” Catchy title. You can tell right away … Continue reading RustSec Integrity Breach Hides Dangerous Crypto Flaw →
You must log in or # to comment.

