top | item 46438491

(no title)

CiPHPerCoder | 2 months ago

I found several libraries that simply didn't implement the check, but none that implemented in incorrectly in the same way as the vulnerability discussed above.

If you didn't receive an email from me, either your implementation isn't listed on https://ianix.com/pub/ed25519-deployment.html, I somehow missed it, or you're safe.

discuss

order

F3nd0|2 months ago

Thank you for your work on free software.

pseudohadamard|2 months ago

[deleted]

CiPHPerCoder|2 months ago

> Did you also check all of the libraries that implement the check differently to libsodium?

Yes, but it was a breadth-first search sourced from the ianix webpage, so I certainly missed some details somewhere. I'll continue to search over the coming weeks in my spare time (if I can get any).