theupdateframework / theupdateframework/specification
Clearly specify how to optionally defend against slow-retrieval attacks
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 405
- Forks
- 59
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 1
Description
Following up on #111: on second thought and some discussion, I think that we should reinstate slow-retrieval attacks in the spec, but only if we make it optional (because not everyone has control over their network stacks), and make it clear how to do so (e.g., moving average download speed must be X bytes/sec).
What do others think?
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading issue #111 and the linked Slack discussion to understand the prior decision about slow-retrieval attacks. Then review the specification sections affected by that decision. Done means the spec clearly describes an optional defense and defines how a moving-average download-speed threshold should be applied.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100