HiveMinds / HiveMinds/tw-install

Test if sync works with 1 letter changed in the certificate.

Open
#13 0 comments 0 reactions 0 assignees View on GitHub
documentation Security Testing
Dominant language
Shell
Stars
20
Forks
7
PR merge metrics
No merged PRs in 30d

Description

To test the security of the setup, first verify the sync functions properly, then modify 1 letter in the certificates and check if the sync worked.


Test for scenarios:



  1. Change in host:

    1.1 Modify a single character in: ca.cert.pem

    1.1 Modify a single character in: .cert.pem

    1.1 Modify a single character in: ,key.pem

  2. Change in client

    2.1 Modify a single character in: ca.cert.pem

    2.1 Modify a single character in: .cert.pem

    2.1 Modify a single character in: ,key.pem


And report the results here and in a general text describing the weaknesses in the security of the current implementation of this installation procedure of taskwarrior.


Contributor guide

No contributing guide indexed for this repository

Research direction

Start by verifying that sync works before changing any files. Then test the host and client scenarios by changing one character in ca.cert.pem, .cert.pem, and ,key.pem, recording whether synchronization still works. Report the results here and in a general text describing weaknesses in the installation procedure's security.

Written by the indexing model from the issue text.

Assessment

Tech stack
shell
Domain
cli, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.