A Vulnerability in Libsodium

38 points | by raggi 2 hours ago

3 comments

  • CiPHPerCoder 35 minutes ago

    This also affected the PHP library, sodium_compat. https://github.com/FriendsOfPHP/security-advisories/pull/756

    I'm planning to spend my evening checking every other Ed25519 implementation I can find to see if this check is missing any where else in the open source ecosystem.

  • proof_by_vibes 25 minutes ago

    I've been iterating on sodium bindings in Lean4 for about four months, and now that I've gotten to Ristretto255 I can see why the author is excited about its potential. Ristretto is a tightly designed API that allows me to build arbitrary polynomials on Curve25519 and I've been having a blast tinkering and experimenting with it! If the author by chance reads this, just want to say thank you for your work!

  • gafferongames 6 minutes ago

    Such a great library. Thank you Frank Denis