154 points•lostmsu•7 days ago•58 comments•

58 comments

Aurornis7 days ago
> What is the issue?

> Network traffic between nodes is not encrypted and not authenticated.

Oh.

After all of the work they put into using cryptographic identities and decentralization tricks, how did they forget to do anything about the network traffic?

Was this a case of thinking they'd handle it later, but then it fell off the TODO list?

dkmb7 days ago
Reading the blog, it sounds more like they were depending on libraries (both by Cyphernet, interestingly) and implicitly trusting them, instead of verifying.

Which I can understand to an extent with large, high-traffic dependencies but these were really low traffic projects with like 10 stars on github and barely any development... Well, hindsight is 20/20.

Aurornis7 days ago
Do you mean this blog post? https://maninak.com/blog/radicle-cleartext-transport-vulnera...

It's unfortunate that write-up is AI generated ("Here's the catch... And this is the part that honestly surprised me" tipped me off, and Pangram cites it as 100% AI too), because it's hard to understand what's happening.

It looks like the Noise API can be confusing. They tried to implement it, got the handshake and key exchange right, but then used Noise API calls intended for sending raw data directly to the wire without the encryption they set up? So keys were exchanged, then never used?

john_strinlai7 days ago
>This was reported to us by Konstantinos Maninakis on 2026-06-24.

announcement 3 months later is not super great, considering that the current advice is "Stop using private repositories (over the network) until the security update is released."

vocx2tx7 days ago
Also: user guide still mentions supporting private repositories [0]

FAQ still says that "Radicle supports private repositories [...] completely invisible to the rest of the network" [1]

[0] https://radicle.dev/guides/user#initializing-a-private-repos...

[1] https://radicle.dev/faq

gsaslis7 days ago
Thank you for noticing. We need to fix that.
conartist67 days ago
I was floored that they emailed me about it for the first time today saying "of course you already know all the details from the blog post".

Me: "No!"

gsaslis7 days ago
For the record, that is not what the Zulip announcement wrote. Please don't kick us when we're down.
sondr37 days ago
The fact that this was reported three months ago and the "workaround" is to stop using private repos and assume they are all pwnd is quite something. How do you not notice that cross-node traffic is not encrypted when building something like this?
jscd7 days ago
Radicle has been one of those projects that had seemed interesting, but something always bothered me about it. (I think it was very highly tied to the cryptocurrency movement for a while? And the Cyphernet GitHub org seems to have rebranded from a DAO?)

This, unfortunately, kinda seals the deal on never using this thing, at least not for anything I intend to keep private. This isn't about proficiency in some protocol which has XYZ footgun: they never checked that payloads were encrypted. Ridiculous.

skullone7 days ago
This whole project reads like amateur hour. Still using curl pipe to shell install and everything. Plus this lax security disclosure with just an outstandingly foolish security flaw. Gross.
hirako20007 days ago
It's a team of 3. It's not like they have a security team, dedicated testers. They were for very long releasing beta software. That in fact already worked.
zitterbewegung7 days ago
If a core feature of your software requires security guarantees you can't just say they don't have a "security team" .
skullone7 days ago
Could be a solo person or a team of 5,000. This is amateur hour, and they are not serious about their purported secure and private platform.
Veserv7 days ago
Oh, so when they advertise “Your Data, Forever and Secure”[1] in big bold letters on their homepage with total disregard for the truth of that statement they are just committing fraud. Got it.

[1] https://radicle.dev/

Arrowmaster7 days ago
To be fair even the largest companies are still using curl piped to sh in their Linux install instructions. And they are all fucking imbeciles.

Read the full thread on Hacker News →

Related stories