Correct the security claims in docs and comments, and record the accepted risks (closes #171)
Docs and comments only; no behaviour change. Corrects ten overclaims the security review found: snapshot names are hashed but the hash uses no secret, so a guessed hostname and name can be confirmed; a blob is named by hex(SHA256(SHA256(uncompressed contents))), stated once in docs/REPOSTRUCTURE.md and referenced elsewhere; double hashing does not hide known content (blob packing does); age uses ChaCha20-Poly1305, not XChaCha20; encryption is required, not optional; a snapshot is marked complete before its metadata is uploaded; the export comment now matches its only caller; deep verify detects corruption, not authorship; adding a recipient does not reach existing data; restore examples target a user-owned directory. Adds an Accepted Risks subsection under Security Considerations with the seven documented risks, cross-referenced from the README. Model: opus-4-8
This commit was merged in pull request #199.
This commit is contained in:
@@ -16,11 +16,17 @@ import (
|
||||
)
|
||||
|
||||
// DoubleSHA256 returns the double SHA-256 of content whose single SHA-256
|
||||
// digest is sum: it hashes that digest once more. Stored objects are named by
|
||||
// this second hash so that a name never reveals whether known content is
|
||||
// present — an attacker who knows a plaintext, and thus its SHA-256, still
|
||||
// cannot derive the stored name without hashing the digest again. Both a blob
|
||||
// and the metadata database export are named this way.
|
||||
// digest is sum: it hashes that digest once more. Stored objects — a blob, and
|
||||
// the metadata database export — are named by this second hash.
|
||||
//
|
||||
// The second hash does not hide whether known content is stored: an attacker
|
||||
// who can reproduce an object's entire plaintext computes the same name simply
|
||||
// by hashing twice, exactly as this code does. What limits that is blob
|
||||
// packing, not the double hash — a blob's name covers all of its concatenated
|
||||
// chunk plaintext, so a name can be confirmed only by someone who can
|
||||
// reproduce the whole blob (a snapshot made entirely of known content, or a
|
||||
// known file large enough to fill blobs on its own). An ordinary file that
|
||||
// shares a blob with other, unknown data cannot be confirmed this way.
|
||||
func DoubleSHA256(sum []byte) []byte {
|
||||
h := sha256.Sum256(sum)
|
||||
|
||||
@@ -147,8 +153,8 @@ func (w *Writer) Close() error {
|
||||
|
||||
// ContentID returns the double SHA-256 of the uncompressed input data: the
|
||||
// name under which this content is stored. It is the second hash of the
|
||||
// running SHA-256, via DoubleSHA256; see that function for why content is
|
||||
// named this way rather than by its plain SHA-256.
|
||||
// running SHA-256, via DoubleSHA256; see that function for what naming content
|
||||
// this way does and does not hide.
|
||||
func (w *Writer) ContentID() []byte {
|
||||
return DoubleSHA256(w.hasher.Sum(nil))
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user