

“The nonce reuse issue seems to be a valid security issue, but it is by no means a critical vulnerability: it only affects applications that do more than four billion encryptions with a single HPKE setup,” said Valsorda. “The average application does one.”
No implementation should be using the same asymmetric keypair for a key exchange* more than once. This is such a non-issue that it’s kind of hilarious. Sounds like the reporter was trying so desperately to get credit for anything they could put on their portfolio, and just wouldn’t take “no” for an answer.




No, but that won’t stop me from having fun trying, will it?