Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security #10

Closed
jsuchal opened this issue Apr 4, 2021 · 2 comments
Closed

Security #10

jsuchal opened this issue Apr 4, 2021 · 2 comments
Projects
Milestone

Comments

@jsuchal
Copy link
Member

jsuchal commented Apr 4, 2021

Tu je diskusia ohladom security:

Kedze podpisovanie je extremne chulostiva operacia s dalekosiahlymi dosledkami (viem previest cely svoj majetok), tak si musime davat velky pozor.

  • okienko, kde sa zobrazuje vizualizacia musi byt extremne osekany sandbox. vypol by som tam JS aj vsetko. Pre PDF bude povoleny pdf.js
  • webview na vizualizaciu sa smie pouzivat len na vizualizaciu a nic ine. tlacitko "podpisat", musi byt uplne mimo tohto.
  • http server nesmie byt otvoreny do sveta, ale dostupny len lokalne. ak ma niekto staticku ipcku, urcite nechceme, aby mu tam niekto "zvonka" nieco podstrcil.
  • hodil by sa aj nejaky security audit, ked budeme mat alfa verziu hotovu.
@jsuchal jsuchal added this to the Discovery milestone Apr 4, 2021
@jsuchal jsuchal added this to To do in Podpisovač Apr 4, 2021
@jsuchal jsuchal moved this from To do to In progress in Podpisovač Apr 4, 2021
@durasj
Copy link
Contributor

durasj commented Apr 8, 2021

Dalsiu vec, ktoru bude treba ceknut pri implementacii custom protocolu je https://www.vdoo.com/blog/exploiting-custom-protocol-handlers-in-windows a ekvivalentne bezpecnostne starosti pri ostatnych OS.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Podpisovač
In progress
Development

No branches or pull requests

3 participants