Cryptocat founder apologizes over bug that made some types of messages more vulnerable to snooping. The vulnerability, found by Steve Thomas, affected group chats and not private conversations. The encryption keys used to encode those conversations were too short, which in theory made it easier for an attacker to decrypt and read conversations. Kobeissi: “I am not a person who will gloss over this kind of bug for absolutely no reason just to maintain the image of the project” He gave Thomas a US$250 reward out of his own pocket even though the application has no formal bug bounty program.”]

