Comments

  • redsand@infosec.pub
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 months ago

    3 year old subpackage blob. Maybe it’s from before the switch to PQC? They have a published threat model that helped guide the audits and seemed well reasoned. I’m not sure where that version of curve would be used in the current client or server.

      • redsand@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        you can message the developers directly from the client. Ask, if they dont know why it’s there it’ll get stripped out. I would guess it’s legacy compatibility but it could be zombie code that needs pruned

        • Soatok Dreamseeker@pawb.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          Why would I want to use the client? :S

          I’m just here to criticize cryptographic open source software. I don’t actually want to use these programs.