47ng / 47ng/local-state-sync

Security Concerns

Ouverte
#1 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
Aucune donnée de langage
Étoiles
3
Forks
0
Métriques de merge des PR
Aucune PR mergée en 30 j

Description

Hello, First I want to thank you for your effort to the open source community.

I saw in the doc you said that:

`"It will not be secure against an attacker that inspects the source code of the page (eg: browser extensions) to find the key and can run arbitrary scripts on your origin to decrypt the stored state."`

Can you please give some light on this statement, or give us a real world example on how an attacker could reach the private key?

Thank you.

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Piste de recherche

The issue asks for clarification on a security statement in the documentation. Start by reviewing the project's README or docs to understand the encryption mechanism and key storage. Look for existing discussions or code in the repository about key exposure risks. Research browser extension capabilities and same-origin policy attacks to provide a real-world example. The answer should explain how an attacker with source code access could extract the key and decrypt state.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Domaine
security
Type d'issue
Documentation
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.