47ng / 47ng/local-state-sync

Security Concerns

オープン
#1 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
言語のデータがありません
スター
3
フォーク
0
PR マージ指標
30日以内にマージされた PR はありません

説明

Hello, First I want to thank you for your effort to the open source community.

I saw in the doc you said that:

`"It will not be secure against an attacker that inspects the source code of the page (eg: browser extensions) to find the key and can run arbitrary scripts on your origin to decrypt the stored state."`

Can you please give some light on this statement, or give us a real world example on how an attacker could reach the private key?

Thank you.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

The issue asks for clarification on a security statement in the documentation. Start by reviewing the project's README or docs to understand the encryption mechanism and key storage. Look for existing discussions or code in the repository about key exposure risks. Research browser extension capabilities and same-origin policy attacks to provide a real-world example. The answer should explain how an attacker with source code access could extract the key and decrypt state.

索引モデルが issue の本文から書いたものです。

評価

領域
security
issue の種類
ドキュメント
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。