monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] Monotone Security


From: Daniel Carrera
Subject: Re: [Monotone-devel] Monotone Security
Date: Thu, 16 Oct 2008 18:22:02 +0200
User-agent: Thunderbird 2.0.0.17 (Macintosh/20080914)

Jack Lloyd wrote:
Regardless of whether this stops the DOS attack or not, I think that it is important that the dates on the certificates be trustworthy.

That is really really hard. In fact it seems pretty much impossible,
especially for backdating. That's because there does not seem to be
any obvious way to distinguish between a certificate that I signed a
long time ago, and you are now just seeing (due a sync/push), and one
that I just now intentionally and maliciously backdated.

I think in Monotone is it more useful to reason about causality using
the explicit revision graph rather than try to bring trusted global
clocks into it.

Reasoning about causality would go a long way: Never trust a revision that is dated earlier than its parent. And it appears to address the specific DOS attacks that Peter found.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]