Hacker News new | ask | show | jobs
by daira 4454 days ago
This issue (or one with very similar effect) was also found by the Least Authority audit: https://github.com/cryptocat/cryptocat/issues/607

(The 'issue E' that it references is https://github.com/cryptocat/cryptocat/issues/606 .)

1 comments

Actually I strongly suggest reading these in conjunction with iSec's issues 12 through 16, because each team spotted some details that the other missed.
Are you sure that's not because the different teams had different scopes? The iSEC audit was specifically tied to the iOS application.
The scopes had a great deal of overlap; although we (Least Authority) didn't consider the iOS client at all, the rest of iSec's audit has essentially the same scope as ours. The point I was trying to highlight is how easy it is to miss things, and therefore that having independent concurrent audits is actually a really good idea. It would probably be even better if the teams worked mostly independently but were able to exchange draft versions of their reports (before the mitigations necessary for a public release).