Skip to content
This repository has been archived by the owner on Jan 9, 2018. It is now read-only.

Please retire this gem and label it as "unsafe" in the README #15

Open
tarcieri opened this issue Apr 19, 2017 · 1 comment
Open

Please retire this gem and label it as "unsafe" in the README #15

tarcieri opened this issue Apr 19, 2017 · 1 comment

Comments

@tarcieri
Copy link

Please retire this gem. It contains multiple, extremely severe security vulnerabilities:

Either of these vulnerabilities can, depending on the circumstances, lead to full plaintext recovery.

I opened #12 nearly 4 months ago. The extremely severe issue in #4 is approaching 4 years old.

This gem is broken, insecure, and unsuitable for use, and yet it is also the top hit for "ruby aes gem". Please retire it and point people at something safer, like ActiveSupport::MessageEncryptor:

http://api.rubyonrails.org/classes/ActiveSupport/MessageEncryptor.html

@rosenmoore
Copy link

Agree 100%. This gem could easily snare a passer-by who is unfamiliar with symmetric key encryption and believes it is safe.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants