Block a user
security(useragent): validate server cert fingerprint and host instead of accepting all certificates
I appreciate the effort, but sadly this is wrong solution. So first of all, we pin based on root CA, not leaf CA. This means that we check if signer that signed presented certificate by server…
suspicious as keywords
I agree. The problem with those is that fucking sqlite dynamically sizes integers. So fucking diesel implement ToSql for sqlite only for i32.
refactor(hashing): introduce Hashable derive macro and migrate server types
Post-quantum crypto and better useragent security
Client key is not integrity-protected
WIP: Post-quantum crypto and better useragent security
Not using quantum-resistant schemes
Bootstrap token comparison is not constant-time
User-agent auth accepts integrity-unavailable state while sealed
User-agent auth accepts integrity-unavailable state while sealed
Currently it's intended behaviour, because vault could be sealed and verification couldn't be performed