David Wong

cryptologie.net

cryptography, security, and random thoughts

Hey! I'm David, cofounder of zkSecurity, research advisor at Archetype, and author of the Real-World Cryptography book. I was previously a cryptography architect of Mina at O(1) Labs, the security lead for Libra/Diem at Facebook, and a security engineer at the Cryptography Services of NCC Group. Welcome to my blog about cryptography, security, and other related topics.

← back to all posts

Tarsnap: No heartbleed here

blog

There’s a few reasons for this. First, the Tarsnap client-server protocol does not use TLS

I was also lucky: The Tarsnap webserver happens to be running an older version of OpenSSL which never had the vulnerable code

http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html

For those who are curious about the protocol that Tarsnap uses : it’s explained here

← back to all posts blog • 2014-04-10
currently reading:
Tarsnap: No heartbleed here
04-10 blog
📖 my book
Real-World Cryptography is available from Manning Publications.
A practical guide to applied cryptography for developers and security professionals.
🎙️ my podcast
Two And A Half Coins on Spotify.
Discussing cryptocurrencies, databases, banking, and distributed systems.
📺 my youtube
Cryptography videos on YouTube.
Video explanations of cryptographic concepts and security topics.