Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Claude discovers a novel enzyme system with CRISPR-like repeats(anthropic.com)
    308comments
  2. Fixing the Portobello Police Station Clock(pointinthecloud.com)
    74comments
  3. A brief history of Windows scroll bar shortcuts(devblogs.microsoft.com/oldnewthing)
    35comments
  4. Italian parliament votes for return to nuclear energy(apnews.com)
    239comments
  5. LensVLM: Compressing long context as images, expanding only relevant pages(huggingface.co)
    discuss
  6. Gemini 3.8 text-to-speech(blog.google)
    105comments
  7. Jev in 25 Lines of Python(nobodywho.ai)
    190comments
  8. Radicle: Disclosure of Vulnerability in the Network Protocol(radicle.dev)
    36comments
  9. Tokens too cheap to meter(jyn.dev)
    160comments
  10. DoorDash Spent $1.4M Trying to Stop Mamdani from Becoming Mayor. Now We Know Why(theintercept.com)
    74comments
  11. Show HN: An atlas of system designs with interactive architecture diagrams(atlas-sysdes.vercel.app)
    5comments
  12. I don't want the details(michaelheap.com)
    176comments
  13. OpenAI Medicare Data Breach(smh.com.au)
    4comments
  14. Z80 REPL (2018)(abagames.github.io)
    18comments
  15. Claude Code reads AGENTS.md only when telemetry is on [fixed](szypowi.cz)
    238comments
  16. Stripe's Knowledge AI Platform(stripe.dev)
    99comments
  17. Once Claude can measure something, it can make it faster(claude.dev)
    70comments
  18. UK military jamming other nations' satellites to defend itself, BBC told(bbc.com)
    158comments
  19. Making Tailscale Faster(tailscale.com)
    discuss
  20. Swap, ZRAM, Zswap and Hibernate on NixOS(matthewbrunelle.com)
    3comments
  21. Show HN: I built a post-mortem debugger for native Windows x64/x86 crashes(forensicdbg.com)
    discuss
  22. Show HN: Conway's Game of Life in boot sector(github.com/0xax)
    3comments
  23. Seattle City Council votes to ban surveillance pricing in sale of groceries(consumerreports.org)
    137comments
  24. QuestDB (YC S20) Is Hiring a Sales Engineer(questdb.com)
    discuss
  25. Strands Harness(strandsagents.com)
    89comments
  26. Web-based IBM 1620 emulator and IPL-V from 1963(github.com/pkimpel)
    8comments
  27. Transit rewards(waymo.com)
    310comments
  28. GPT-6 Sol and Luna(openai.com)
    820comments
  29. 28% of job postings on company career sites have been open over 90 days(unlisted.careers)
    262comments
  30. What California is learning from solar panels built over irrigation canals(kqed.org)
    683comments

Radicle: Disclosure of Vulnerability in the Network Protocol

100 pointsby 6h agoradicle.dev
36 comments
5h agoHN ↗

I honestly thought there would be some elaborate chain there, not "we forgot to use encryption"...

5h agoHN ↗

Honestly issues like this crop up pretty commonly. JWT alg:none for example. Or even older people forcing SSL to downgrade to encryption null.

In any system that provides security it should only be designed to run if the security is in use, and to fail immediately with no further action if the security is not used.

4h agoHN ↗

And not using authentication.

Peer authentication in the connection handshake is broken and allows impersonation. An attacker can connect to your node and present a Node ID that is not its own. Private repositories are shared only with allow-listed Node IDs. An attacker who fakes an allow-listed Node ID can fetch a private repository directly, without being on the network path. This was reported to us by cryptocode on 2026-08-12. We proposed a fix upstream, see this pull request.

They are trying to sweet write it as much as possible. But basically there is neither encryption nor authentication. The person who made the protocol/program simply didn't care.

4h agoHN ↗

I find this to be very telling about what kind of people they are. If you make a mistake this big you need to own up to it. BS all you want, maybe you think that works for you.. but people see through it.

2h agoHN ↗

They probably forgot to tell Claude to make no mistakes.

But seriously, the fact that this started as Crypto-adjacent should have immediately disqualified them for serious use.

5h agoHN ↗

My main wish is if radicle had a way to make issues online, without installing the software. Runing a piece of software is a high barrier of entry to make a bug report, which the entire reason I use codeberg instead.

5h agoHN ↗

That's a downside of all decentralised software, isn't it? If there's a convenient access point, that access point is also a point of centralisation. To be distributed, you have to be running the software yourself. The big problem is that the software always ends up being inconvenient. People have no problem using bittorrent because the software is actually usable.

4h agoHN ↗

Like onion/ipfs/many others, I'd expect gateways to pop up if it grows relatively popular. If LLM scrapers don't destroy them immediately, at least.

2h agoHN ↗

My main wish is a way to search the repositories on a node. Or a way to have tags. The whole network is like a blackbox of projects unless you can get an outside link.

5h agoHN ↗

This was reported to us by Konstantinos Maninakis on 2026-06-24.

announcement 3 months later is not super great, considering that the current advice is "Stop using private repositories (over the network) until the security update is released."

1h agoHN ↗

Thank you for noticing. We need to fix that.

4h agoHN ↗

I was floored that they emailed me about it for the first time today saying "of course you already know all the details from the blog post".

Me: "No!"

1h agoHN ↗

For the record, that is not what the Zulip announcement wrote. Please don't kick us when we're down.

4h agoHN ↗

you're right! i can't believe i only noticed that just now, thanks!

4h agoHN ↗

Is there a risk that other projects that may be using the same cyphernet-labs/netservices.rs code, like Nym & Farcaster, have also been expecting authentication & encryption where it hasn't been happening?

4h agoHN ↗

This whole project reads like amateur hour. Still using curl pipe to shell install and everything. Plus this lax security disclosure with just an outstandingly foolish security flaw. Gross.

3h agoHN ↗

It's a team of 3. It's not like they have a security team, dedicated testers. They were for very long releasing beta software. That in fact already worked.

2h agoHN ↗

If a core feature of your software requires security guarantees you can't just say they don't have a "security team" .

6m agoHN ↗

Oh, so when they advertise “Your Data, Forever and Secure”[1] in big bold letters on their homepage with total disregard for the truth of that statement they are just committing fraud. Got it.

[1] https://radicle.dev/

1h agoHN ↗

To be fair even the largest companies are still using curl piped to sh in their Linux install instructions. And they are all fucking imbeciles.

4h agoHN ↗

The fact that this was reported three months ago and the "workaround" is to stop using private repos and assume they are all pwnd is quite something. How do you not notice that cross-node traffic is not encrypted when building something like this?

3h agoHN ↗

What is the issue?

Network traffic between nodes is not encrypted and not authenticated.

Oh.

After all of the work they put into using cryptographic identities and decentralization tricks, how did they forget to do anything about the network traffic?

Was this a case of thinking they'd handle it later, but then it fell off the TODO list?

3h agoHN ↗

Reading the blog, it sounds more like they were depending on libraries (both by Cyphernet, interestingly) and implicitly trusting them, instead of verifying.

Which I can understand to an extent with large, high-traffic dependencies but these were really low traffic projects with like 10 stars on github and barely any development... Well, hindsight is 20/20.

2h agoHN ↗

Do you mean this blog post? https://maninak.com/blog/radicle-cleartext-transport-vulnera...

It's unfortunate that write-up is AI generated ("Here's the catch... And this is the part that honestly surprised me" tipped me off, and Pangram cites it as 100% AI too), because it's hard to understand what's happening.

It looks like the Noise API can be confusing. They tried to implement it, got the handshake and key exchange right, but then used Noise API calls intended for sending raw data directly to the wire without the encryption they set up? So keys were exchanged, then never used?

23m agoHN ↗

Correct, I was referring to the original linked article/disclosure.

3h agoHN ↗

Glad to hear they are moving to iroh instead of a custom protocol. This is the problem with rolling your own stuff.

As a bonus, this should help camouflage the traffic. (Iroh is becoming more common.)

2h agoHN ↗

Radicle has been one of those projects that had seemed interesting, but something always bothered me about it. (I think it was very highly tied to the cryptocurrency movement for a while? And the Cyphernet GitHub org seems to have rebranded from a DAO?)

This, unfortunately, kinda seals the deal on never using this thing, at least not for anything I intend to keep private. This isn't about proficiency in some protocol which has XYZ footgun: they never checked that payloads were encrypted. Ridiculous.

2h agoHN ↗

The network protocol used by Radicle does not give the confidentiality it was expected to give. Anyone who can observe the network path between two nodes can read the data they exchange as the data is sent in plain text.

Is this a... design choice? This feels like too egregious of an omission to be a regular vulnerability here.