This is the tweet to link to, to end this silly debate.https://twitter.com/tqbf/status/996056901514420224 …
-
-
I'm sure we can argue about just how clear usage requirements were, but when someone takes a decade+ old crypto flaw and uses it together with application logic mistakes and security issues, the correct response isn't "PGP is terrible, broken and doomed, stop using it".
-
The entire thing hinges on two scenarios: out of context decryption (100% an application layer problem) and in-context mutation (abuses known malleability problem; ignoring error code from mitigations is an application layer problem) all relying on an app layer back channel.
- Show replies
New conversation -
-
-
You’re missing the problem that the text/pipe interface is likely the API bug that reliably creates this failed behavior across most (almost all?) implementations. Bad interfaces yield bad behaviors.
-
It’s a critical failure being returned as a mostly untyped non-blocking comment.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.