monotone-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Monotone-devel] Monotone Security


From: Ethan Blanton
Subject: Re: [Monotone-devel] Monotone Security
Date: Thu, 16 Oct 2008 14:01:08 -0400
User-agent: Mutt/1.5.17+20080114 (2008-01-14)

Daniel Carrera spake unto us the following wisdom:
>> All security has to go in the *recipient*, because the
>> sender could be completely malicious. 
>
> Of course. Every check I have suggested has been server-side  
> (recipient). The client (sender) is completely malicious.

The server isn't (necessarily) a trusted entity.  When you grok that,
perhaps your positions will change.  :-)

Ethan

-- 
The laws that forbid the carrying of arms are laws [that have no remedy
for evils].  They disarm only those who are neither inclined nor
determined to commit crimes.
                -- Cesare Beccaria, "On Crimes and Punishments", 1764

Attachment: signature.asc
Description: Digital signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]