2020-12-19 06:47:22
https://www.bleepingcomputer.com/news/security/bouncy-castle-crypto-authentication-bypass-vulnerability-revealed/ A severe authentication bypass vulnerability has been reported in Bouncy Castle, a popular open-source cryptography library. When exploited, the vulnerability (CVE-2020-28052) can allow an attacker to gain access to user and administrator accounts due to a cryptographic weakness in the manner passwords are checked.
Rotonen
2020-12-19 06:48:07
is the quality of the ecosystem like that through the whole stack?
Rotonen
2020-12-19 20:09:13
I haven't had any concerns, but I haven't been looking for cryptographic problems like that
Fireduck
2020-12-19 20:13:38
mostly the quality of review and testing brcomes the immediate worry
Rotonen
2020-12-19 20:17:07
yeah
Fireduck