[wp-trac] [WordPress Trac] #39309: Secure WordPress Against Infrastructure Attacks

WordPress Trac noreply at wordpress.org
Tue Feb 6 18:31:21 UTC 2018


#39309: Secure WordPress Against Infrastructure Attacks
------------------------------------------+-----------------------
 Reporter:  paragoninitiativeenterprises  |       Owner:
     Type:  enhancement                   |      Status:  reopened
 Priority:  normal                        |   Milestone:
Component:  Upgrade/Install               |     Version:  4.8
 Severity:  critical                      |  Resolution:
 Keywords:  has-patch reporter-feedback   |     Focuses:
------------------------------------------+-----------------------
Changes (by johnbillion):

 * keywords:  has-patch => has-patch reporter-feedback


Comment:

 What sort of peer review has the sodium_compat library had? In the repo
 description it says:

 > This cryptography library has not been formally audited by an
 independent third party that specializes in cryptography or cryptanalysis.

 Is this still the case? You mentioned in Slack that Joomla now uses this
 library. Has it therefore been audited? Are you aware of any other
 projects using the library?

 Thanks.

--
Ticket URL: <https://core.trac.wordpress.org/ticket/39309#comment:33>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list