monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] WARNING: ~/.monotone/keys CONSIDERED HARMFUL


From: Brian May
Subject: Re: [Monotone-devel] WARNING: ~/.monotone/keys CONSIDERED HARMFUL
Date: Mon, 20 Oct 2008 12:43:25 +1100
User-agent: Thunderbird 2.0.0.17 (X11/20080925)

Brian May wrote:
I think fixing this would be well worth it even if it did mean making backwards incompatible changes.

I thought I should just mention using hashes is only part of the solution - once hashes are used to identify keys, we would need some sort of hash --> user mapping so we can securely work out what key belongs to what user.

Hmmm. Now I think about it, I suspect there is currently no real security on mapping keys to email addresses - it is assumed that the data received and stored in the database is valid and trusted.

Identifying all keys by hashes, which are fixed for a given key, would be a good first step to rectify this.

Brian May




reply via email to

[Prev in Thread] Current Thread [Next in Thread]