Improve Security Boundary for TOFU URLs
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 45/100
Línea de trabajo
Start with HubHostTrustValidator and the trustedHubAuthorities storage, then inspect the trust prompt and the "Trusted Hub Hosts" settings screen. Compare the Android design with cryptomator/cryptomator#4309 and determine how existing trusted entries are handled. Done means trust is evaluated for URL combinations rather than independently, with the stored data, prompt, and settings UI consistent.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
Before Cryptomator connects to unknown URLs (i.e. when unlocking a Hub vault), users have to review and trust these URLs. Currently, such URLs are trusted independently. This means once trusted, these URLs can be mixed (i.e. in a Hub vault config). To increase security, we should extend the trust concept to sets of URLs. If two already-trusted URLs belong to two different sets, they are not trusted in combination.
This is the Android counterpart of cryptomator/cryptomator#4309.
Motivation
The Hub vault config contains two endpoints: authEndpoint and apiBaseUrl. Cryptomator follows the TOFU principle to trust these URLs.
The app-internal trust check (HubHostTrustValidator) validates both against a flat, app-wide trusted-hosts set (trustedHubAuthorities) independently, without confirming that they belong to the same trusted Hub instance. This means a vault config is still accepted when it is edited such that authEndpoint/tokenEndpoint point to an already-trusted Hub host A, but apiBaseUrl points to a different, also already-trusted host B.
Such edits should be made visible to the user, and trust should be requested again for that specific combination.
Considered Alternatives
No response
Anything else?
This affects the stored shape of trustedHubAuthorities, the trust prompt, and the "Trusted Hub Hosts" settings screen. We also have to decide what happens to entries that users already trusted.
This issue was found by Aakarshit Bargotra and they responsibly disclosed it to us.
Note that this is not a vulnerability, because the TOFU principle still holds: Both URLs have to be trusted.
- Lenguaje dominante
- Kotlin
- Estrellas
- 1.2k
- Forks
- 216
- Merge medio
- 1 d 20 h
- PR fusionados (30 d)
- 9
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de cryptomator/android
-
Increase Cache Size?Abiertotype:feature-request
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
cryptomator/android#666 ·
Los mantenedores suelen responder en 1 día
-
"Keep unlocked" advanced setting on Android app doesn't release Vault after files are closedAbierto
Dificultad 3/5 1-2 días Aptitud para principiantes 55/100
cryptomator/android#656 ·
Los mantenedores suelen responder en 1 día
-
state:to-be-confirmed type:bug
Dificultad 4/5 3-5 días Aptitud para principiantes 68/100
cryptomator/android#654 ·
Los mantenedores suelen responder en 1 día
-
Using custom CA certificatesAbiertotype:feature-request
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
cryptomator/android#653 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Android IntegrationAbiertotype:feature-request
Dificultad 5/5 Más de una semana Aptitud para principiantes 30/100
cryptomator/android#647 · 1 reacción ·
Los mantenedores suelen responder en 1 día
Todos los issues de cryptomator/android
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
ankidroid/Anki-Android#22408 ·
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 Menos de una hora Aptitud para principiantes 72/100
afarber/OpenMapView#22 ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
nightscout/AndroidAPS#5245 ·
Los mantenedores suelen responder en 1 día
-
Feature:Resolution
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
intellij-elixir/intellij-elixir#4396 ·
Los mantenedores suelen responder en 1 día