frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We found cryptography bugs in the elliptic library using Wycheproof

https://blog.trailofbits.com/2025/11/18/we-found-cryptography-bugs-in-the-elliptic-library-using-wycheproof/
106•crescit_eundo•1w ago

Comments

binkHN•1d ago
FYI: two vulnerabilities in elliptic, a widely used JavaScript library for elliptic curve cryptography
some_furry•1d ago
The maintainer seems to have abandoned it: https://github.com/indutny/elliptic/issues

I wrote a shim library and posted it on their issue tracker: https://github.com/indutny/elliptic/issues/343

Unfortunately, adoption seems slow. I'm talking with a few people about how to move the ecosystem to something more secure like noble-curves, but it's tricky.

thephyber•22h ago
If you really feel like helping the ecosystem update, you could file issues/PRs for all of the downstream NPM modules to switch to your shim library.

Remember to tell them what the problem is and how your library solves it.

some_furry•22h ago
If you click "Show more" you'll see this: https://imgur.com/a/KLI8cjL
tuananh•21h ago
> One vulnerability is still not fixed after a 90-day disclosure window that ended in October 2024. It remains unaddressed as of this publication.

curious why now. should they public it last year after 90-day disclosure window ended?

tptacek•21h ago
They can publish it whenever they want. There's no actual rules about this stuff. The 90 window is a courtesy.
pseudohadamard•15h ago
Specifically, there are responsible disclosure guidelines that came about to deal with the problem of people dropping 0day on a vendor with no prior warning. So the 90 days is a commonly-accepted amount of time to give a vendor to produce a fix. If the vendor needs more time they can request that the submitter give them an extension, although in this case it appears the vendor never responded, thus the repeated entries in the timeline saying "tried to contact vendor, no response" to show they tried to do the right thing.
tptacek•7h ago
No there aren't. "Responsible disclosure" is an Orwellian term invented by vendors to create the idea that publishing independent research without vendor permission is "irresponsible". It is absolutely not the case that researchers owe anybody 90 days, or are obligated to honor requests for extensions. Project Zero, which invented the 90-day-plus-extension system, does that as a courtesy.
dadrian•5h ago
The 90-day disclosure window is an arbitrary courtesy, not a binding contract about the behavior of either party. They probably had other things to do.
throwaway81523•17h ago
It's very hard to get stuff right with the secp curves. That's one of the reasons for the move to curve25519 and similar. The book "Guide to Elliptic Curve Cryptography" by Hankerson, Menezes, and Vanstone is mostly very careful step by step instruction of how to do secp* arithmetic properly. It would still be useful to have some formal verification to help the assurance of of any particular implementation.
pseudohadamard•15h ago
25519 just brings in a different set of problems though, see for example https://hdevalence.ca/blog/2020-10-04-its-25519am, and @mmsc's post above which barely scratches the surface.
Ar-Curunir•7h ago
There are complete formulae for all prime-order Weierstrass curves. The work for secure implementation of prime-order curves is now simpler than for Edwards elliptic curves.
mmsc•17h ago
(2024).

There are other vulnerabilities in that library too. I reported some (with some PRs) https://github.com/indutny/elliptic/pull/338, https://github.com/indutny/elliptic/pull/337, https://github.com/indutny/elliptic/issues/339 but I assume they'll never get fixed.

The library is dead and should be marked as vulnerable on npmjs tbh.

How to Code Claude Code in 200 Lines of Code

https://www.mihaileric.com/The-Emperor-Has-No-Clothes/
172•nutellalover•3h ago•112 comments

Sopro TTS: A 169M model with zero-shot voice cloning that runs on the CPU

https://github.com/samuel-vitorino/sopro
62•sammyyyyyyy•2h ago•28 comments

SQL Studio

https://sql.studio/
55•handfuloflight•1h ago•35 comments

Bose is open-sourcing its old smart speakers instead of bricking them

https://www.theverge.com/news/858501/bose-soundtouch-smart-speakers-open-source
1921•rayrey•7h ago•291 comments

The Unreasonable Effectiveness of the Fourier Transform

https://joshuawise.com/resources/ofdm/
91•voxadam•3h ago•42 comments

Google AI Studio is now sponsoring Tailwind CSS

https://twitter.com/OfficialLoganK/status/2009339263251566902
331•qwertyforce•3h ago•119 comments

The Jeff Dean Facts

https://github.com/LRitzdorf/TheJeffDeanFacts
352•ravenical•9h ago•132 comments

Fixing a Buffer Overflow in Unix v4 Like It's 1973

https://sigma-star.at/blog/2025/12/unix-v4-buffer-overflow/
64•vzaliva•4h ago•16 comments

AI coding assistants are getting worse?

https://spectrum.ieee.org/ai-coding-degrades
158•voxadam•7h ago•208 comments

Mux (YC W16) is hiring a platform engineer that cares about (internal) DX

https://www.mux.com/jobs
1•mmcclure•1h ago

Show HN: macOS menu bar app to track Claude usage in real time

https://github.com/richhickson/claudecodeusage
50•RichHickson•4h ago•21 comments

Show HN: A geofence-based social network app 6 years in development

https://www.localvideoapp.com
11•Adrian-ChatLocl•1h ago•4 comments

Ushikuvirus: Newly discovered virus may offer clues to the origin of eukaryotes

https://www.tus.ac.jp/en/mediarelations/archive/20251219_9539.html
46•rustoo•18h ago•11 comments

Digital Red Queen: Adversarial Program Evolution in Core War with LLMs

https://sakana.ai/drq/
73•hardmaru•6h ago•7 comments

Iran Protest Map

https://pouyaii.github.io/Iran/
8•breppp•34m ago•0 comments

IBM AI ('Bob') Downloads and Executes Malware

https://www.promptarmor.com/resources/ibm-ai-(-bob-)-downloads-and-executes-malware
216•takira•4h ago•103 comments

Task-free intelligence testing of LLMs

https://www.marble.onl/posts/tapping/index.html
26•amarble•3h ago•5 comments

Lights and Shadows (2020)

https://ciechanow.ski/lights-and-shadows/
215•kg•6d ago•30 comments

PgX – Debug Postgres performance in the context of your application code

https://docs.base14.io/blog/introducing-pgx/
8•rshetty•1d ago•3 comments

Making Magic Leap past Nvidia's secure bootchain and breaking Tesla Autopilots

https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/making-the-magic-leap-past-nvidia-s-s...
10•rguiscard•1w ago•3 comments

Support for the TSO memory model on Arm CPUs (2024)

https://lwn.net/Articles/970907/
13•weinzierl•2h ago•10 comments

Project Patchouli: Open-source electromagnetic drawing tablet hardware

https://patchouli.readthedocs.io/en/latest/
411•ffin•17h ago•47 comments

I used Lego to design a farm for people who are blind – like me

https://www.bbc.co.uk/news/articles/c4g4zlyqnr0o
88•ColinWright•3d ago•27 comments

A closer look at a BGP anomaly in Venezuela

https://blog.cloudflare.com/bgp-route-leak-venezuela/
362•ChrisArchitect•16h ago•193 comments

Intellectual Junkyards

https://www.forester-notes.org/QHXS/index.xml
25•ysangkok•3d ago•6 comments

Iran Goes Into IPv6 Blackout

https://radar.cloudflare.com/routing/ir
344•honeycrispy•6h ago•254 comments

Dell admits consumers don't care about AI PCs

https://www.pcgamer.com/hardware/dells-ces-2026-chat-was-the-most-pleasingly-un-ai-briefing-ive-h...
338•mossTechnician•1d ago•253 comments

Texas court blocks Samsung from tracking TV viewing, then vacates order

https://www.bleepingcomputer.com/news/security/texas-court-blocks-samsung-from-tracking-tv-viewin...
42•speckx•2h ago•11 comments

Open Infrastructure Map

https://openinframap.org
407•efskap•19h ago•91 comments

Richard D. James aka Aphex Twin speaks to Tatsuya Takahashi

https://web.archive.org/web/20180719052026/http://item.warp.net/interview/aphex-twin-speaks-to-ta...
14•lelandfe•1h ago•8 comments