webwormhole icon indicating copy to clipboard operation
webwormhole copied to clipboard

FYI: Is this potentially vulnerable? (CVE-2021-31603)

Open IljaN opened this issue 4 years ago • 1 comments

Croc Full Plaintext Recovery https://redrocket.club/posts/croc/

IljaN avatar Apr 30 '21 20:04 IljaN

Thanks for sharing the link! It's a good read. Croc's post about fixing the issues discovered is also here: https://schollz.com/blog/croc9/

The PAKE we use is CPace instead of SPAKE2. Specifically, the filippo.io/cpace implementation. By my reading today, I don't believe an analogous vulnerability applies here. That said, I'll leave this open until I hear back from second opinion. :)

saljam avatar May 01 '21 21:05 saljam