[tahoe-lafs-trac-stream] [tahoe-lafs] #1665: Brainstorm webapi vulnerabilities between the operator and a user and between users.

tahoe-lafs trac at tahoe-lafs.org
Wed Jan 25 05:20:58 UTC 2012


#1665: Brainstorm webapi vulnerabilities between the operator and a user and
between users.
-----------------------------------+-----------------------
     Reporter:  nejucomo           |      Owner:
         Type:  task               |     Status:  new
     Priority:  major              |  Milestone:  undecided
    Component:  code-frontend-web  |    Version:  n/a
   Resolution:                     |   Keywords:
Launchpad Bug:                     |
-----------------------------------+-----------------------

Comment (by nejucomo):

 A '''mitigation''' for comment:5 would be to improve the introduction
 system and/or accounting to separate out capabilities for discovering
 storage nodes, introducing storage nodes, or requesting storage.  (Again,
 I'm unfamiliar with the current state of accounting, so this vulnerability
 may soon be well mitigated.)

-- 
Ticket URL: <https://tahoe-lafs.org/trac/tahoe-lafs/ticket/1665#comment:6>
tahoe-lafs <https://tahoe-lafs.org>
secure decentralized storage


More information about the tahoe-lafs-trac-stream mailing list