Forums before death by AOL, social media and spammers... "We can't have nice things"
|    alt.privacy    |    Discussing privacy, laws, tinfoil hats    |    112,125 messages    |
[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]
|    Message 111,614 of 112,125    |
|    Gabx to All    |
|    Re: aliceandbob pgp tool    |
|    18 Sep 25 11:01:56    |
      XPost: alt.privacy.anon-server, misc.test       From: victor@virebent.tcpreset              SEC3 wrote:> Pretty neat: https://aliceandbob.io/       >       > This post is exclusively about the online version of aliceandbob.io:              I've just completed a security review of the Alice & Bob Go implementation       (https://github.com/aliceandbob-io/aliceandbob ) and must raise a serious red       flag: there is no runtime protection for private keys in memory.              Unlike hardened implementations, like the one written by myself       (e.g., https://github.com/gabrix73/Nofuture-Go-Memguard ),              https://safecomms.virebent.art/              which use memory locking, anti-dump measures, ptrace restrictions, and       defense-in-depth against local root compromise, Alice & Bob's code:              Stores private keys in regular Go heap memory (subject to GC, swapping, core       dumps).              Does not lock pages with mlock or equivalent.              Does not disable core dumps or restrict /proc/ |
[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]
(c) 1994, bbs@darkrealms.ca