Skip to content

Introduce new comment payload (only used in Facebook integration)#12378

Merged
Jack-Works merged 1 commit intodevelopfrom
comment-upgrade
May 6, 2026
Merged

Introduce new comment payload (only used in Facebook integration)#12378
Jack-Works merged 1 commit intodevelopfrom
comment-upgrade

Conversation

@Jack-Works
Copy link
Copy Markdown
Member

The original version of the comment payload reuses the post encryption IV for comments, which is cryptographically insecure.
A bugrap user reported this to us. Although the attack POC is not clear, I added the per-comment IV to the comment payload.

@Jack-Works Jack-Works merged commit 5ab6733 into develop May 6, 2026
11 of 12 checks passed
@Jack-Works Jack-Works deleted the comment-upgrade branch May 6, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant