Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create static metadata that demonstrates attacks #360

Closed
vladimir-v-diaz opened this issue Aug 9, 2016 · 3 comments
Closed

Create static metadata that demonstrates attacks #360

vladimir-v-diaz opened this issue Aug 9, 2016 · 3 comments

Comments

@vladimir-v-diaz
Copy link
Contributor

We should expand the Security page to include static metadata that simulates known attacks (e.g., replay attack, freeze attack, etc.). This metadata can be fed to other implementations to verify that they correctly handle these attacks.

@vladimir-v-diaz
Copy link
Contributor Author

The repository management document was updated to demonstrate some of the attacks TUF detects: https://github.com/theupdateframework/tuf/tree/526d7507fa21c71b5f938557f982f757241d3e98/tuf#blocking-malicious-updates

@awwad
Copy link
Contributor

awwad commented Feb 26, 2019

@lukpueh
Copy link
Member

lukpueh commented Feb 23, 2022

The section in the repository management document mentioned above was later moved to an attack demo document, which was recently removed as it had become severely outdated. #1798 suggests to reinstate an up-to-date version of the document. So I'd say we can close here. (I will add a note to #1798 about feeding demo data into other implementations)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants