Changes between Version 19 and Version 20 of News


Ignore:
Timestamp:
2007-08-24T16:43:24Z (17 years ago)
Author:
zooko
Comment:

announce Tahoe v0.5.1

Legend:

Unmodified
Added
Removed
Modified
  • News

    v19 v20  
    33== Latest News ==
    44
    5 === 2007-08-21 -- security flaw ===
     5=== 2007-08-23 -- Allmydata Tahoe v0.5.1 released! ===
    66
    7 Nathan Wilcox has discovered that the new web API in allmydata-tahoe
    8 version 0.5 is vulnerable to XSRF attack.  An XSRF -- or "Cross-Site
    9 Reference Forgery" attack -- is one in which an attacker creates an
    10 innocuous-looking hyperlink, and if a user clicks on that hyperlink
    11 then it causes deletion or theft of the user's data.  We are working
    12 on a fix for this problem, and in the meantime if you have stored any
    13 private or precious data on a tahoe grid, then you can make sure that
    14 you are not exposed to this threat by shutting down your tahoe node
    15 before browsing the web.
     7This fixes a security flaw in Tahoe v0.5.0.
    168
    17 You can read more about the attack and our fix in the mailing list archves:
    18 
    19 http://allmydata.org/pipermail/tahoe-dev/
    20 
    21 and in this bug tracker ticket:
    22 
    23 http://allmydata.org/trac/tahoe/ticket/98
    24 
    25 === 2007-08-17 -- Allmydata Tahoe v0.5 released! ===
    26 
    27 This version adds a RESTful API allowing you to program your Tahoe node in the language of your choice, as well as a command-line API in the Unix style, and some performance improvements.
    28 
    29 Please see [source:relnotes.txt@1129 the Release Notes].
     9Please see [source:relnotes.txt@1154 the Release Notes].
    3010
    3111== Old News ==