Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer  ·  activity timestamp 8 hours ago

Ah, the Matrix guy decided to chime in on the Hacker News thread about my blog.

https://news.ycombinator.com/item?id=46979742#46982871

Of course his comment is bullshit.

Discord Alternatives | Hacker News

  • Copy link
  • Flag this post
  • Block
Kye Fox
Kye Fox
@Kye@tech.lgbt replied  ·  activity timestamp 7 hours ago

@soatok Matrix bros vibe choading

  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer replied  ·  activity timestamp 7 hours ago

Like, the issues I found aren't even particularly difficult to mitigate. I provided some sample code in my Matrix disclosure blog post and pointed to a bitsliced AES implementation (BearSSL) for systems that can't do AES-NI.

Hell, you could probably get a fucking LLM to do it. Trail of Bits published a Claude skill for detecting whether a compiler has undermined the intent for code to be constant-time. But the heavy-lifting is done by a Python script.

Shipping cryptography without side-channels was table-stakes for being taken seriously.

GitHub

skills/plugins/constant-time-analysis at main · trailofbits/skills

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows - trailofbits/skills
Dhole Moments

Security Issues in Matrix’s Olm Library

I don’t consider myself exceptional in any regard, but I stumbled upon a few cryptography vulnerabilities in Matrix’s Olm library with so little effort that it was nearly accidental. It…
  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer replied  ·  activity timestamp 7 hours ago

The Matrix guy is incentivized to control the narrative here. No surprise there.

But I implore anyone paying attention to critically evaluate the facts and what he said then as well as what he's saying now.

  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer replied  ·  activity timestamp 7 hours ago

There are more pathetic comments on the Hacker News thread.

For example:

(Would you believe this guy has -18 karma?)

Dumb anti-furry comment on HN:

"I would've consider some of this, but with all the furry crap, not going to happen."
Dumb anti-furry comment on HN: "I would've consider some of this, but with all the furry crap, not going to happen."
Dumb anti-furry comment on HN: "I would've consider some of this, but with all the furry crap, not going to happen."
  • Copy link
  • Flag this comment
  • Block
Soatok Dreamseeker
Soatok Dreamseeker
@soatok@furry.engineer replied  ·  activity timestamp 6 hours ago

The crucial thing Arathorn hasn't figured out is he's his own worst enemy when it comes to public relations.

Several folks have told me they stopped trusting Matrix. But not because of my write-up. They stopped trusting Matrix because of how Matrix responded to my write-up.

They couldn't just said something banal like, "Thanks for contributing to the security of Matrix," and done less damage to their own reputation.

  • Copy link
  • Flag this comment
  • Block
Risotto Bias
Risotto Bias
@risottobias@toot.risottobias.org replied  ·  activity timestamp 6 hours ago

@soatok a good amount of my own judgement on a company is how they recover from an attack or treat a security researcher.

hostility? not purchasing.

owning up to it with public whitepaper / lessons learned? awesome.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.23 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct