Article 78K04 Critical security vulnerabilities in the Radicle network protocol

Critical security vulnerabilities in the Radicle network protocol

by
jzb
from LWN.net on (#78K04)

The Radicle peer-to-peercode-collaboration project has disclosedtwo critical vulnerabilities in the network protocol used by Radiclenodes. The first flaw is that the network protocol used by Radicle "does notgive the confidentiality it was expected to give", which allows anyone whocan observe the network between two nodes to read the data exchanged. The secondis that peer authentication is broken and allows impersonation, so an attackercan spoof their Node ID and read private repositories they should not be able toread.

In practice, the two flaws are most useful when they can be exploitedtogether: an attacker on the path sees the Node IDs at both ends of aconnection, and both are normally on the allow-list. That attacker can readwhatever is exchanged while they watch, and can then use a Node ID they saw tofetch the whole repository on demand. The realistic threat is anyone on the pathbetween your node and node it syncs with, and no setting or allow-list protectsagainst them.

We are publishing this before the security update is available. You can acton it today, and no fix we release later can undo an exposure that has alreadyhappened.

See the post for workarounds that can be used today; a major update that willbe backward-incompatible is underway.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments