From Gemini deep research

...

In conclusion, the debate surrounding the suitability of JavaScript for security-sensitive development is multifaceted.

The elliptic vulnerability serves as a significant reminder of the potential risks involved in cryptographic _implementations_. (Emphasis mine)

However, it should not lead to an outright rejection of JavaScript. Instead, it should foster a more informed and cautious approach, emphasizing the critical role of secure development practices and the continuous need for vigilance in the ever-evolving field of cybersecurity.

The choice of programming language for security-sensitive applications should be a carefully considered decision based on a thorough understanding of the specific security requirements, the capabilities and limitations of the language, and the expertise of the development team.

Reply to this note

Please Login to reply.

Discussion

lol, llm slop. The ECC code is orders of magnitude less meaningful code review than the canonical bitcoin core implementation