Client key replacement attack #40
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Suppose vault was created locally.
Useragent unseal the vault and disconnects / idles.
Malware could:
Proposed solutions:
First solution is more straightforward, but second is better in terms of UX.
useragent pubkey entry couldn't be verified before unseal, but this doesn't matter because vault is sealed either way and malicious client would need to know unseal password.