Hasty Briefsbeta

双语

Radicle: Disclosure of Vulnerability in the Network Protocol

2 hours ago
  • Two critical vulnerabilities in Radicle's network protocol were reported: data is transmitted in plaintext (no encryption), and peer authentication is broken, allowing impersonation.
  • These flaws allow attackers on the network path to read data and potentially fetch private repositories by faking allow-listed Node IDs.
  • Users are advised to stop using private repositories until a fix is released, and to block seeding of private repositories to prevent further exposure.
  • The proposed fix involves migrating to the iroh networking stack, which will be a breaking change requiring a major version update.
  • Past exposure cannot be undone, so users should consider any transmitted private data as leaked and rotate any exposed credentials.