Cryptographic Issues in Matrix’s Rust Library Vodozemac - Dhole Moments

View Archive →

Two years ago, I glanced at Matrix's Olm library and immediately found several side-channel vulnerabilities. After dragging their feet for 90 days, they ended up not bothering to fix any of it. The Matrix.org security team also failed to notify many of the alternative clients about the impending disclosure--a fact that became more annoying when…

Shared by. . .
9
visit article