ietf-wg-wimse / draft-ietf-wimse-arch

Draft of a WIMSE architecture document
Other
2 stars 7 forks source link

Information Disclosure == Credential Theft? #20

Open PieterKas opened 3 months ago

PieterKas commented 3 months ago

Should we distinguish between information disclosure (attacker learns information it should not have) vs attacker obtains control of a credential that it can use to impersonate a workload, perform lateral moves or elevate privelage.

jsalowey commented 3 months ago

I think so. There is an intersection between lateral movement capability and information disclosure, but they are not the same thing and its probably imprortant to differentiate the different outcomes.