EricssonResearch / EricssonResearch/Blind-Cache-Drafts

Prevent CDN Exploitation

Open
#3 12 comments 0 reactions 0 assignees View on GitHub
oob
Dominant language
Makefile
Stars
2
Forks
2
PR merge metrics
No merged PRs in 30d

Description

The current model contains no proof for the CDN that the origin actually referred it. 7.2 defines using the encryption/integrity keys as proof _to the client_ that the origin actually can decrypt the content. An attacker who wished to spoof the origin could not only retrieve and rehost the content, but even use the same CDN address and key to steal the CDN's hosting services for its attack.

It seems like there needs to be something to demonstrate to the CDN that the requestor has (recently?) spoken to the origin server.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.