- Radicle, a code-sharing app like GitHub, says every version it has released sends code between computers without encryption.
- Anyone who can see the traffic between two Radicle computers can read the code those computers send each other while watching.
- Radicle shares private projects only with approved computers, but a second bug lets attackers who know an approved computer's ID pose as it.
- Radicle has no fix yet and tells people to stop sharing private projects over the network until one ships.
- Radicle says passwords or keys kept unencrypted inside private projects already shared with another computer should be changed.
Radicle, a code-sharing app like GitHub, said on September 23 that every version it has released sends code between computers without encryption. Anyone who can see the traffic between two Radicle computers can read the code they send each other while watching, private projects included. Radicle also disclosed a second bug that lets attackers pose as trusted computers. There's no fix yet.
Radicle network protocol vulnerability disclosure
Unlike GitHub, Radicle has no central server. People run it on their own computers, which send code straight to each other. Software engineer Konstantinos Maninakis found the missing encryption and reported it to Radicle on June 24. He writes that internet providers and others along the path between two computers can read everything sent, private projects included.
Maninakis unencrypted Radicle traffic report
Radicle only shares a private project with approved computers, each known by an ID. A second bug, reported August 12 by someone called cryptocode, lets an attacker's computer claim an approved computer's ID. The approved list isn't public, but Radicle says someone watching a connection sees the IDs at both ends. That person could then use one of those IDs to download the whole project.
LWN Radicle vulnerabilities report
Radicle tells people to stop sharing private projects over the network until a fix ships, and to treat any already shared as leaked. Passwords or keys kept unencrypted inside those projects should be changed. Radicle says a VPN or Tor, tools that hide internet traffic, limit the attack but aren't enough. A targeted attack might still copy a private project by faking an approved computer's ID.
Radicle says the bugs let attackers read code but not secretly change it, because Radicle computers detect code altered on the way. Radicle plans to switch to iroh, an open source networking tool that Maninakis says encrypts connections. Work is under way, with no date yet. Computers with the fix won't be able to connect to older Radicle versions.
On Hacker News, some commenters criticized Radicle for waiting about 3 months after the first report to warn people. Others asked how a project offering private code sharing never noticed its traffic wasn't encrypted.




