A security report says Xray-core shipped a bug that let connections skip proper TLS certificate checks - and that the problem was kept quiet instead of fixed in the open.
The claim surfaced in a GitHub issue filed on net4people/bbs, a forum that tracks tools people use to get around internet censorship. According to the report, Xray-core - a widely used fork of the V2Ray proxy framework - contained a flaw that allowed certificate verification to be bypassed, undermining the TLS encryption that is supposed to protect users from interception. The issue frames this as concealment rather than a disclosed-and-patched bug. The discussion reached Hacker News, where it picked up 67 points and nine comments, modest but notable traction for a niche networking report.
Xray-core underpins proxy setups that activists, journalists, and ordinary users in restrictive countries depend on to reach the open internet. A certificate bypass is not a cosmetic bug - it is the exact failure mode that lets a network operator, or anyone positioned to intercept traffic, impersonate a server and read what is supposed to be encrypted. If the flaw was concealed rather than disclosed, that adds a trust problem on top of a technical one, for software whose entire value proposition is holding up under adversarial conditions.
Circumvention tools live and die on that trust; a hidden crypto bug is exactly the kind of thing that sends users looking for the next fork.