Soatok Dreamseeker @soatok@furry.engineer · activity timestamp 22 hours ago Oof. Big oof.https://blog.trailofbits.com/2026/02/18/carelessness-versus-craftsmanship-in-cryptography/ Read more Read less Translate The Trail of Bits Blog Carelessness versus craftsmanship in cryptography Two popular AES libraries (aes-js and pyaes) provide dangerous default IVs that lead to key/IV reuse vulnerabilities affecting thousands of projects. One maintainer dismissed the issue, while strongSwan’s maintainer exemplified proper security response by comprehensively fixing the vulnerability in their VPN management tool. Reply Boost or quote Boost Quote You cannot quote this post Like More actions Copy link Flag this post Block