mozilla / addons

☂ Umbrella repository for Mozilla Addons ✨
Other
127 stars 41 forks source link

sign MLBF kinto attachments #7360

Closed eviljeff closed 4 years ago

eviljeff commented 4 years ago

for MLBF attachments (#13616) to be trusted we need to sign them and include the signature in the kinto record submission.

eviljeff commented 4 years ago

https://bugzilla.mozilla.org/show_bug.cgi?id=1621615 for the autograph bug

eviljeff commented 4 years ago

On the back of a recent meeting the current thinking is that signing the bloomfilter is ineffective against the kinds of attacks we'd want to prevent so closing this for now 😞