40 minutes ago an anigma user claiming to be a security researcher contacted me to inform me of a vulnerability on anigma. He definitively demonstrated that he knew my private key and gave plausible evidence it was because anigma had a vulnerability to cross site scripting. He informed me of a way to resolve the issue and I did as he suggested. He asks me to inform everyone that this vulnerability has been live practically since anigma started so everyone who has used it should get new private keys.

Reply to this note

Please Login to reply.

Discussion

Probably shouldn't use the same key in every client :D

An external signing app/service thing would probably be a good idea to use the same key with different clients with less risk

#[1]