Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Include warning that the encryption as implemented is not secure and it should not be used. the issues are summarized in this issue
#1273
the mode / encryption algorithm needs to be AES-GCM, AES-CBC-AEAD-HMAC, or X/ChaCha20-Poly1305 to be considered secure. The other issues also need to be fixed. AES-GCM is hard to implement correctly as such its probably better to choose a different method.
As for the warning people should be aware the current encryption will not protect their data. The website should also be updated to have a warning.