Theregister
Dispute Erupts Over RustSec Bug Reports and Cryptography Vulnerabilities
Article Content
Cryptographer Nadim Kobeissi has been attempting to address critical vulnerabilities in Rust cryptography libraries since February 2026. His efforts to publish advisories for these vulnerabilities have led to his dismissal and subsequent ban from Rust security channels. Kobeissi filed a complaint with the Rust Moderation Team and later escalated it to The Rust Foundation, alleging a violation of the Code of Conduct. He claims to have discovered critical vulnerabilities in the hpke-rs crate, including a nonce-reuse issue that could enable full AES-GCM plaintext recovery. However, his approach has been criticized by fellow cryptographer Filippo Valsorda, who argues that Kobeissi's actions were not in good faith. The controversy centers around the handling of bug reports and the response from Cryspen, a cryptographic software firm, which maintains that no bugs were found in its verified code. Kobeissi asserts that four vulnerabilities were identified, leading to a public dispute over the credibility of formal verification versus practical testing. The situation remains unresolved as discussions continue within the Rust community.
Key Points: • Nadim Kobeissi claims to have found critical vulnerabilities in Rust cryptography libraries. • Kobeissi has faced dismissal and a ban after attempting to publish security advisories. • The dispute highlights tensions between formal verification and practical testing in cryptographic software.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.