Skip to content

Should responses include calculated digest? #3

@Acconut

Description

@Acconut

The current draft recommends server to include the expected digest value in an error response when the digest provided by the client doesn't match the server's expectation. This opens the door to potential information leakage and oracle attacks, which potentially allows an attacker to learn about the data over which the digest was computed.

Should we remove this recommendation to include the digest calculated by the server?

Is there a good way to get an expert's opinion in this topic? Maybe through a secdir early review?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions