Urgent.News

What's breaking now, across thousands of outlets.

Tech

Radicle: Disclosure of Vulnerability in the Network Protocol

Radicle, a peer-to-peer code-collaboration project, has revealed two critical vulnerabilities in its network protocol. The first flaw allows the lack of confidentiality, which enables any observer to read the data exchanged between two nodes. The second issue stems from broken peer authentication, allowing attackers to impersonate Node IDs and gain access to private repositories they should not be able to read.

When these two flaws are combined, an attacker in the network path can not only read the exchanged data but also fetch the entire repository using a Node ID they have observed. The real threat lies in anyone on the path between your node and its syncing node, and no setting or allow-list can provide protection against this. The disclosure comes before a security update, urging immediate action since no fix can undo past exposures.

Workarounds are available for immediate use, while a major update is being prepared that will be backward-incompatible.

Written by urgent.news from LWN's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at radicle.dev →

More in Tech

How Jev Works: The Logit Trick Behind TypeSafe's System One Model

For the last few weeks my timeline has been nothing but Jev. TypeSafe AI shipped it, and within days there was an awesome-jev list, a jev-mcp server, a LangChain integration, and about ten thousand…

  • Jev is a closed, fast classification model running on TypeSafe's servers
  • Logit trick converts model's prefill scores into single token responses
  • Jev provides fast, accurate, limited responses without free text

More from Wednesday 23 September →