logoalt Hacker News

Aurornistoday at 7:24 PM1 replyview on HN

Do you mean this blog post? https://maninak.com/blog/radicle-cleartext-transport-vulnera...

It's unfortunate that write-up is AI generated ("Here's the catch... And this is the part that honestly surprised me" tipped me off, and Pangram cites it as 100% AI too), because it's hard to understand what's happening.

It looks like the Noise API can be confusing. They tried to implement it, got the handshake and key exchange right, but then used Noise API calls intended for sending raw data directly to the wire without the encryption they set up? So keys were exchanged, then never used?


Replies

gsaslistoday at 8:25 PM

That is the article of the reporter.

I believe the blog post being referred to here is the one linked to in the title (i.e. https://radicle.dev/2026/09/23/disclosure-of-vulnerability-i...)

show 1 reply