-
Notifications
You must be signed in to change notification settings - Fork 0
Closed
Description
The current draft recommends server to include the expected digest value in an error response when the digest provided by the client doesn't match the server's expectation. This opens the door to potential information leakage and oracle attacks, which potentially allows an attacker to learn about the data over which the digest was computed.
Should we remove this recommendation to include the digest calculated by the server?
Is there a good way to get an expert's opinion in this topic? Maybe through a secdir early review?
Metadata
Metadata
Assignees
Labels
No labels