Audit Open Original ↗
Ockam
Type
Security review
Client
Ockam
Date
2023-11
Domain
Crypto
Effort
11 wks
Section
Cryptography Reviews
Trail of Bits's security review of Ockam (Nov 2023) identified 6 issues: 3 medium, and 3 informational.
Findings · 6
- 1 The system is vulnerable to SNDL attacks by quantum computers Medium
- 2 Serialized VersionedData struct’s data is ambiguous Informational
- 3 Truncating ChangeHistory hash to 160 bits introduces risk of collisions Informational
- 4 The meanings of the primary key fields created_at and expires_at are undocumented Medium
- 5 Insu cient threat model documentation Medium
- 6 The supported signature schemes have di erent security properties Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related