{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2021:E64K5W253C4UGS6S6WF7NVKB6H","short_pith_number":"pith:E64K5W25","schema_version":"1.0","canonical_sha256":"27b8aedb5dd8b9434bd2f58bf6d541f1f0e064ca34a1d65b008a11609f1cb4c6","source":{"kind":"arxiv","id":"2107.04940","version":1},"attestation_state":"computed","paper":{"title":"You Really Shouldn't Roll Your Own Crypto: An Empirical Study of Vulnerabilities in Cryptographic Libraries","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Daniel J. Weitzner, Jenny Blessing, Michael A. Specter","submitted_at":"2021-07-11T02:09:52Z","abstract_excerpt":"The security of the Internet rests on a small number of open-source cryptographic libraries: a vulnerability in any one of them threatens to compromise a significant percentage of web traffic. Despite this potential for security impact, the characteristics and causes of vulnerabilities in cryptographic software are not well understood. In this work, we conduct the first comprehensive analysis of cryptographic libraries and the vulnerabilities affecting them. We collect data from the National Vulnerability Database, individual project repositories and mailing lists, and other relevant sources f"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2107.04940","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2021-07-11T02:09:52Z","cross_cats_sorted":[],"title_canon_sha256":"c28eadd10fa027b3e315bb91a453b8f61aec4bab27426b3a00e0ecefb3e5cf06","abstract_canon_sha256":"1b435b80570b2981753090a75ff6a157b3f3f6f221e3b60456a0dbcf9bd6f04c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T02:56:44.521608Z","signature_b64":"gD6v7cbKfGNSnIkerQZ9BwjlFSKUPln4p9IHLN+YVt+EEiZH1G/3kI43CDQGLHkz+xbVvXsCHI7iiEDbV1sPDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"27b8aedb5dd8b9434bd2f58bf6d541f1f0e064ca34a1d65b008a11609f1cb4c6","last_reissued_at":"2026-07-05T02:56:44.521191Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T02:56:44.521191Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"You Really Shouldn't Roll Your Own Crypto: An Empirical Study of Vulnerabilities in Cryptographic Libraries","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Daniel J. Weitzner, Jenny Blessing, Michael A. Specter","submitted_at":"2021-07-11T02:09:52Z","abstract_excerpt":"The security of the Internet rests on a small number of open-source cryptographic libraries: a vulnerability in any one of them threatens to compromise a significant percentage of web traffic. Despite this potential for security impact, the characteristics and causes of vulnerabilities in cryptographic software are not well understood. In this work, we conduct the first comprehensive analysis of cryptographic libraries and the vulnerabilities affecting them. We collect data from the National Vulnerability Database, individual project repositories and mailing lists, and other relevant sources f"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2107.04940","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2107.04940/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2107.04940","created_at":"2026-07-05T02:56:44.521249+00:00"},{"alias_kind":"arxiv_version","alias_value":"2107.04940v1","created_at":"2026-07-05T02:56:44.521249+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2107.04940","created_at":"2026-07-05T02:56:44.521249+00:00"},{"alias_kind":"pith_short_12","alias_value":"E64K5W253C4U","created_at":"2026-07-05T02:56:44.521249+00:00"},{"alias_kind":"pith_short_16","alias_value":"E64K5W253C4UGS6S","created_at":"2026-07-05T02:56:44.521249+00:00"},{"alias_kind":"pith_short_8","alias_value":"E64K5W25","created_at":"2026-07-05T02:56:44.521249+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2412.19310","citing_title":"Protecting Cryptographic Libraries against Side-Channel and Code-Reuse Attacks","ref_index":3,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H","json":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H.json","graph_json":"https://pith.science/api/pith-number/E64K5W253C4UGS6S6WF7NVKB6H/graph.json","events_json":"https://pith.science/api/pith-number/E64K5W253C4UGS6S6WF7NVKB6H/events.json","paper":"https://pith.science/paper/E64K5W25"},"agent_actions":{"view_html":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H","download_json":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H.json","view_paper":"https://pith.science/paper/E64K5W25","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2107.04940&json=true","fetch_graph":"https://pith.science/api/pith-number/E64K5W253C4UGS6S6WF7NVKB6H/graph.json","fetch_events":"https://pith.science/api/pith-number/E64K5W253C4UGS6S6WF7NVKB6H/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H/action/timestamp_anchor","attest_storage":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H/action/storage_attestation","attest_author":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H/action/author_attestation","sign_citation":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H/action/citation_signature","submit_replication":"https://pith.science/pith/E64K5W253C4UGS6S6WF7NVKB6H/action/replication_record"}},"created_at":"2026-07-05T02:56:44.521249+00:00","updated_at":"2026-07-05T02:56:44.521249+00:00"}