Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reworded security section about NDEF signature #518

Merged
merged 4 commits into from
Jan 7, 2020

Conversation

beaufortfrancois
Copy link
Collaborator

@beaufortfrancois beaufortfrancois commented Jan 7, 2020

index.html Outdated
these, the NFC Forum introduced [[NDEF-SIGNATURE]].
In order to protect the integrity and authenticity of NDEF messages, the NFC
Forum introduced [[NDEF-SIGNATURE]]. Signing NDEF records prevents malicious
use of NFC tags.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

but it is also the other way around.

This sounds like you harden the tag instead, but it also allows the reader to only accept such hardened tags and thus hardens the reader as well

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That's not how I intended to be understood ;)
How would you rephrase it?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would remove "Signing NDEF records prevents malicious use of NFC tags."
That is inaccurate.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've removed it.

@@ -4080,11 +4080,9 @@ <h3>Parsing content</h3>
<!-- - - - - - - - - - - - - Security and Privacy - - - - - - - - - - - - - -->
<section> <h2 id="security">Security and Privacy</h2>
<p>
NFC technology involves multiple levels of security. Payments done with NFC
are considered to be secure at hardware level, but the whole software stack
needs to be security hardened.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would add a separate sentence, like

"As general security measure, the whole software stack needs to be security hardened".

And place where you think it adds most clarity/value.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems obvious to me and not specific to Web NFC, don't you think?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

IIRC security reviewers insisted on stating the obvious :), but it's the editors' call, indeed.

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

WDYT of ae9e547

@zolkis
Copy link
Contributor

zolkis commented Jan 7, 2020

We already take that data as untrusted.

@beaufortfrancois
Copy link
Collaborator Author

I'll let you update the explainer and I'll remove it.

@beaufortfrancois beaufortfrancois merged commit 5ae742d into w3c:gh-pages Jan 7, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants