Block a user
Post-quantum crypto and better useragent security
Client key is not integrity-protected
WIP: Post-quantum crypto and better useragent security
Not using quantum-resistant schemes
Bootstrap token comparison is not constant-time
User-agent auth accepts integrity-unavailable state while sealed
User-agent auth accepts integrity-unavailable state while sealed
Currently it's intended behaviour, because vault could be sealed and verification couldn't be performed
feat(server): add integrity verification for client keys
feat(server): add integrity verification for client keys