Skip to content

Commit

Permalink
adds explicit SECURITY.md
Browse files Browse the repository at this point in the history
  • Loading branch information
seanwatters committed Jan 31, 2024
1 parent 3b81abd commit e03f23d
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# Security

*THIS CODE HAS NOT BEEN AUDITED OR REVIEWED. USE AT YOUR OWN RISK.*

**WARNING:** the AES256 content key encryption implementation may currently be vulnerable to side-channel
timing attacks due to my lack of expertise as it relates to how much (if anything) the timing of the block
allocations reveals about the underlying bytes being allocated. There is *a* way to do this
correctly, it will just need to be reviewed.

0 comments on commit e03f23d

Please sign in to comment.