hashmapinc / Tempus

Hashmap IIoT Accelerator Framework
Apache License 2.0
29 stars 10 forks source link

Pass key as string instead of byte-array / JCA misuse #1170

Open akwick opened 2 years ago

akwick commented 2 years ago

I am reaching out to you as we conducted an empirical study to understand the nature of cryptographic misuses in enterprise-driven projects on GitHub. During our study, we randomly inspected a few of the misuses. One of the misuses for which we could confirm the finding of the analysis, CogniCryptSAST is within this project.

The report can be reproduced by running CogniCrypt_SAST on the project.

We hope that our assumption is correct and would be glad to get your thoughts on this issue.