Replying to
Radicle, the peer-to-peer Git forge designed by cryptocurrency weirdos, made a little whoopsy-doodle and left the encryption out of their transport layer and the authentication out of the authentication handshake: radicle.dev/…/disclosure-of-vulnerability-in-netw…
Shot:
Anyone who can observe the network path between two nodes can read the data they exchange as the data is sent in plain text.
Chaser:
Peer authentication in the connection handshake is broken and allows impersonation. An attacker can connect to your node and present a Node ID that is not its own.
