47ng / 47ng/local-state-sync

Security Concerns

Aperta
#1 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Nessun dato sulla lingua
Stelle
3
Fork
0
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

Hello, First I want to thank you for your effort to the open source community.

I saw in the doc you said that:

`"It will not be secure against an attacker that inspects the source code of the page (eg: browser extensions) to find the key and can run arbitrary scripts on your origin to decrypt the stored state."`

Can you please give some light on this statement, or give us a real world example on how an attacker could reach the private key?

Thank you.

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Direzione di ricerca

The issue asks for clarification on a security statement in the documentation. Start by reviewing the project's README or docs to understand the encryption mechanism and key storage. Look for existing discussions or code in the repository about key exposure risks. Research browser extension capabilities and same-origin policy attacks to provide a real-world example. The answer should explain how an attacker with source code access could extract the key and decrypt state.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Ambito
security
Tipo di issue
Documentazione
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.