Skip to content
This repository has been archived by the owner on Mar 11, 2024. It is now read-only.

Possible ED25519-dalek issue #209

Open
berendsliedrecht opened this issue Jul 15, 2022 · 0 comments
Open

Possible ED25519-dalek issue #209

berendsliedrecht opened this issue Jul 15, 2022 · 0 comments
Assignees
Labels
bug Something isn't working security
Milestone

Comments

@berendsliedrecht
Copy link
Contributor

According to ed25519-unsafe-libs the library that is used for signing, ed25519-dalek, possibly contains a security bug that allows for private key extraction (as explained in this stack overflow post.

Now, the README mentions that it is not likely that libraries, like Ursa, using the "unsafe" library will also be "unsafe", but I thought I should mention it here.

I am by no means an expert in this, so likely it is just nothing, but it never hurts to mention it.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Something isn't working security
Development

No branches or pull requests

3 participants