Changes between Version 6 and Version 7 of OldNews


Ignore:
Timestamp:
2007-08-24T16:42:34Z (17 years ago)
Author:
zooko
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • OldNews

    v6 v7  
    44
    55== Archived News Items ==
     6
     7=== 2007-08-21 -- security flaw ===
     8
     9Nathan Wilcox has discovered that the new web API in allmydata-tahoe
     10version 0.5 is vulnerable to XSRF attack.  An XSRF -- or "Cross-Site
     11Reference Forgery" attack -- is one in which an attacker creates an
     12innocuous-looking hyperlink, and if a user clicks on that hyperlink
     13then it causes deletion or theft of the user's data.  We are working
     14on a fix for this problem, and in the meantime if you have stored any
     15private or precious data on a tahoe grid, then you can make sure that
     16you are not exposed to this threat by shutting down your tahoe node
     17before browsing the web.
     18
     19You can read more about the attack and our fix in the mailing list archves:
     20
     21http://allmydata.org/pipermail/tahoe-dev/
     22
     23and in this bug tracker ticket:
     24
     25http://allmydata.org/trac/tahoe/ticket/98
    626
    727=== 2007-08-17 -- Allmydata Tahoe v0.5 is released. ===