- Every Radicle version so far sends code between computers without encryption.
- Internet providers and others watching can read that code, even private projects.
- A second bug lets an attacker copy private projects by faking an allowed computer's ID.
- Radicle says to stop sharing private projects online until a fix ships.
Radicle is a code-sharing network like GitHub, but people's computers swap code directly with no central server. Every version Radicle has released sends that code between computers without encryption. So anyone watching the connection, like an internet provider, can read the code as it goes by. That includes private projects, and there's no fix yet.
Radicle network protocol bug disclosure
Software engineer Kostis Maninakis found the bug while building an app that runs Radicle in a web browser. When two Radicle computers connect, they first trade a few short messages to set up the connection. His app encrypted everything after that, the way the encryption method behind Radicle says to. But real Radicle computers couldn't understand it, because they send everything after that opening exchange without encryption.
Maninakis post on Radicle encryption bug
In August, someone going by cryptocode reported a second bug that lets an attacker pretend to be another Radicle computer. Each computer has an ID, and a private project only goes to computers on that project's allowed list. So an attacker who fakes an allowed ID can download a whole private project. The list isn't public, but someone watching a connection sees the IDs at both ends, and those are usually allowed ones.
Radicle says to stop sharing private projects over the network until a fix ships, and to treat any project already shared as leaked. If those projects held unencrypted passwords or keys, change them. Tools that hide internet traffic, like a VPN or Tor, aren't enough on their own. Radicle says a targeted attack might still copy a private project by faking an allowed ID.
The fix changes the way Radicle computers talk, so a fixed computer and an older one won't understand each other. Radicle says that rules out a normal update, so it's working on a new major version instead. There's no date yet. Maninakis says it's planned as Radicle 2.0, which isn't out yet.
Maninakis reported the bug to Radicle privately in June, and they agreed to keep it quiet for about 3 months. Some commenters on Hacker News, a tech forum, say that wait was too long, since the advice now is to stop using private projects.




