top | item 39963222

(no title)

dignifiedquire | 1 year ago

I am not sure if this is an actual issue, all auditors that looked at this so far haven’t mentioned this being a problem. But I will have to investigate what the exact state is.

discuss

order

woodruffw|1 year ago

According to `git blame`, this was introduced June 2023, i.e. after your audit in 2019. But maybe it was moved from an older piece of the codebase, I didn't dig too deep.

(Looks like the IncludeSec folks did a decent job in 2019. Hi Eric!)

dignifiedquire|1 year ago

This was allowed in the rust-rsa crate directly before, which is why it was introduced in that commit.