painless-security / trust-router

Moonshot Trust Router
0 stars 0 forks source link

tids should not return server block on error #22

Open jennifer-richards opened 6 years ago

jennifer-richards commented 6 years ago

In the traces in https://bugs.launchpad.net/moonshot-tr/+bug/1464800, we see that even in an error situation, the tids is returning server blocks. That's almost certainly wrong. Also, I wonder whether the intermediate trust routers should trim out server blocks on error responses to avoid a covert-channel-like-thing where we pretend to the middle something failed, but establish a key anyway.

Launchpad Details: #LP1464804 Sam Hartman - 2015-06-13 01:10:14 +0000