• acockworkorange
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 hours ago

    the author literally picked random projects from github tagged as matrix, without considering their prevalence or whether they are actually maintained etc.

    if you actually look at % of impacted clients, it’s tiny.

    meanwhile, it is very unclear that any sidechannel attack on a libolm based client is practical over the network (which is why we didn’t fix this years ago). After all, the limited primitives are commented on in the readme and https://github.com/matrix-org/olm/issues/3 since day 1.

    From your link.

    • e8d79@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 hours ago

      That is exactly what it says. They knew about security issues in their library and didn’t fix them for years. This isn’t being ignorant, this is negligence.