GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Robert Gützkow (robertguetzkow@infosec.exchange)

  1. Embed this notice
    Robert Gützkow (robertguetzkow@infosec.exchange)'s status on Thursday, 16-Jan-2025 22:17:29 JST Robert Gützkow Robert Gützkow
    in reply to
    • scriptjunkie
    • Dan Goodin

    @sj @dangoodin how would you know whether or not the public key belongs to Alice? Usually in protocols you would have a handshake at the beginning where you'd verify that the sender can sign a message properly. The public key of the sender would have to be known prior and out of band (think certificates like in TLS). Here they just place the public key in the message and use it for the signature verification. As far as I can see, there is nothing in the snippet ensuring that the public key belongs to the sender we are expecting to communicate with.

    In conversation about 6 months ago from infosec.exchange permalink
  2. Embed this notice
    Robert Gützkow (robertguetzkow@infosec.exchange)'s status on Thursday, 16-Jan-2025 11:33:34 JST Robert Gützkow Robert Gützkow
    in reply to
    • scriptjunkie
    • Dan Goodin

    @sj @dangoodin the signature should be validated with a key that you know belongs to the legitimate sender. If you just use the public key that is contained within the very same message you are trying to validate then what is stopping an attacker from supplying a key of their choice?

    In conversation about 6 months ago from infosec.exchange permalink

User actions

    Robert Gützkow

    Robert Gützkow

    IT security, software engineering and digital art. he/him

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          315876
          Member since
          14 Jan 2025
          Notices
          2
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.