What is Nostr?
Matthew Garrett /
npub1aa0…ejrs
2024-08-14 20:51:46

Matthew Garrett on Nostr: FFS. If you *knew* that your cryptography library had weaknesses but you justify that ...

FFS. If you *knew* that your cryptography library had weaknesses but you justify that by arguing that they're probably not real-world exploitable, you really need to be able to explain *why* they're not real-world exploitable, and even if that's true all this should be clearly documented in order to prevent someone else using your code in a way that breaks your assumptions and is vulnerable as a result (re: https://news.ycombinator.com/item?id=41249371)
Author Public Key
npub1aa0gpek8gwr77984c6ufq70j9d5y0hq5xegqrs8dvc4zp0vfzemsuuejrs