top | item 37620316

(no title)

rurcliped | 2 years ago

a recent audit claims the author "doesn't have enough resources to address" security issues: https://www.openwall.com/lists/oss-security/2023/09/08/2 https://github.com/schollz/croc/issues/594 etc.

discuss

order

hn_throwaway_99|2 years ago

I appreciated the links to the audit, but your quote was misleading to me when taken out of context like you did. I interpreted it as basically saying that the author couldn't or wouldn't address the issues identified. The full quote was:

> The upstream author doesn't have enough resources to address them on its own and wants to develop fixes in the open. Therefore I have created GitHub issues in the upstream project and publish the full report today.

I.e. the "and wants to develop fixes in the open" part left me with a very different interpretation from when I first read your comment.

qrv3w|2 years ago

These issues are pretty recent. I would greatly appreciate sponsorship to address issues faster: https://github.com/sponsors/schollz or just help with PRs.

AequitasOmnibus|2 years ago

Just wanted to say that Croc is one of the most reliable and straightforward file transfer tools I’ve ever used. It worked so well that I used it for Android (via Termux) to Windows transfers regularly. I only wish there was a way to use it on iOS but I imagine that’s challenging.

aborsy|2 years ago

There was a deadly security flaw two years ago, that required a protocol breaking fix (done within a week I believe):

https://redrocket.club/posts/croc/

But audits finding vulnerabilities are better than no audit and no known flaw.

Do these tools have iOS apps?