Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

An example where auditors not having the threat model did not help the audit: https://defuse.ca/audits/gocryptfs.htm

> We believe the reason these vulnerabilities exist is because gocryptfs doesn’t have a clearly spelled-out threat model. Some of the attacks seem hard to avoid given gocryptfs’s performance goals and may have been introduced “by design” to meet these goals. We suggest writing down an explicit threat model and updating the website to better communicate the security guarantees that gocryptfs provides. This way, users are less likely to rely on it in ways which would make them vulnerable.

Later established: https://nuetzlich.net/gocryptfs/threat_model/



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: