entropic-dev / entropic-dev/entropic
fingerprint trusted entropic instances
Open
registry
- Dominant language
- JavaScript
- Stars
- 5.2k
- Forks
- 147
- PR merge metrics
- No merged PRs in 30d
Description
The threat model is: somebody inherits the domain name for a server, gets a valid cert for it, and then runs an entropic with malware-injected versions of the packages from the original entropic instance. Proposal: If one entropic instance installs packages from another, they should exchange some kind of fingerprint that identifies them to each other. Sweat the details, find a good solution.
Contributor guide
Assessment
This issue has not been assessed yet.