Trail of Bits

Open Home Foundation SecureTar v3

Type

Security review

Client

Open Home Foundation

Date

2026-03

Domain

Crypto

Effort

1 wk

Section

Cryptography Reviews

Trail of Bits's security review of Open Home Foundation (Mar 2026) identified 3 issues: 1 medium, and 2 informational.

Findings · 3

  1. 1 Timing side channel in validation key comparison Informational
  2. 2 Insecure fallback to legacy protocol version Informational
  3. 3 Supply-chain attacks are possible with GitHub Actions workflows Medium

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related