|
Boost : |
From: Vinnie Falco (vinnie.falco_at_[hidden])
Date: 2024-12-09 19:20:05
On Mon, Dec 9, 2024 at 11:06â¯AM Peter Dimov <pdimov_at_[hidden]> wrote:
> That's a pretty basic quality of implementation issue in this domain.
>
> High quality is always "in scope" for Boost libraries.
>
If it is in scope then should it be documented, with an analysis of attack
vectors and how the library mitigates them? And should there be guidance
for users, who also need to make sure they handle keys in ways that do not
subvert the security guarantees of the library?
Thanks
Boost list run by bdawes at acm.org, gregod at cs.rpi.edu, cpdaniel at pacbell.net, john at johnmaddock.co.uk