@gravifer.bsky.social

Why was this code ever shipped?! This is from the second vuln, where keys' signatures aren't checked before they're stored in the trusted key store. Why would you ever ship a "TODO, actually validate signatures lol" in your secure messenger?!

Image from the Trail of Bits report showing the offending code associated with the second high-severity vulnerability. It includes an empty "else" branch with a "to-do" comment that reads: "TODO (eventually) reject if signature is missing"