People can't help but try to evangelize Matrix in response to things I wrote, so I just disclosed a few more issues in Matrix's cryptography to their security@ email address.

This time, the issues were in their Rust library, vodozemac.

One of them was pretty fucking stupid.

I'll do a better write-up than I was initially planning when they've had time to fix it.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://furry.engineer/users/soatok/statuses/116055556402436098 on your instance and quote it. (Note that quoting is not supported in Mastodon.)