Skip to content

Commit 3ec32eb

Browse files
authored
Update README.md
1 parent 184871f commit 3ec32eb

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

copi.owasp.org/README.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -232,3 +232,8 @@ An attacker can continue to create an unlimited amount of games and players unti
232232
#### What can you do about it?
233233

234234
We are working on minimizing the probability of functionality misue by implementing rate limiting on the creating of games and players (see: [issues/1877](https://github.com/OWASP/cornucopia/issues/1877)). Once that is taken care of, you should be able to configure these limits to prevent DoS attacks when hosting Copi yourself.
235+
236+
### Did we do a good job?
237+
238+
We welcome any input or improvments you might be willing to share with us regarding our current threat model.
239+
Arguably, we created the system before the threat modeling, and several improvements need to be made to properly balance the inherrant risks of compromise against the current security controls. For anyone choosing to host the game engine, please take this into account.

0 commit comments

Comments
 (0)