Hacker News new | past | comments | ask | show | jobs | submit login

[flagged]



IIRC, it was a nonce-not-used-only-once vulnerability, wasn't it? Wouldn't that be tricky to detect, even in Rust?

Regardless, it's quite unfortunate to see Colin's nits picked in this manner, dredging up some mistake from almost 15 years ago (which he handled as responsibly as could be expected), given all of the work he's done on FreeBSD and for giving the world scrypt.


giving the world scrypt

Ironically that bug happened because of scrypt. Creating scrypt led me to refactor Tarsnap's crypto code, which is when the bug slipped in.


Rust would not have prevented that bug.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: