Hacker News·3 min read

Radicle: Disclosure of Vulnerability in the Network Protocol

L
lostmsu
Radicle: Disclosure of Vulnerability in the Network Protocol
Dive DeeperCreate a free account to unlock

Radicle is a peer-to-peer, local-first code collaboration stack built on Git.

Two critical security vulnerabilities in the network protocol used by Radicle nodes were reported.

All versions of Radicle that were released to date are vulnerable.

Network traffic between nodes is not encrypted and not authenticated. Authentication of repository contents via Signed References still detects if attackers along the network path between two nodes modify objects in transit. Thus, the main concern is information leakage, i.e., attackers along the network path between two nodes reading objects in transit. For public repositories, information leakage is less of a concern. However, encryption in transit is crucial for private repositories.

We recommend to stop using private repositories until a fix is released.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in