Re: Creating proxies with different hmac_key

Irmen de Jong <[email protected]> Wed, 30 Oct 2013 01:32:27 +0100
Newsgroups gmane.comp.python.pyro
Message-ID <[email protected]>
On 30-10-2013 0:15, Giovanni Porcari wrote:

> 
> Hi Irmen
> 
> I think that HMAC feature offers us a bit more secure connections
> so i really prefer to have it.
> In last hours I had a very quick look to the code and i tried to
> add this feature (maybe in an ugly way...).
> 
> It seems working to me but of course I am eager to know your opinion.

It may work but it feels "bolted on". I don't really like the mechanism (nor my original
implementation). Then again it probably won't hurt to keep it in there either. I wished
I had the time to design something better, but for the foreseeable future we're stuck
with the current mechanism :-) (Thankfully I've already changed the way the hmac is
added into the wire protocol to a generic mechanism in 4.22)

The patch you provided does leave several things to be desired. Unit tests and
documentation changes also need to be done before it can be applied at all. Thanks for
the effort so far though.

If you use git(hub), and would like to contribute changes, can you do so by pull-request
instead of patches on the mailing list?



Irmen


------------------------------------------------------------------------------
Android is increasing in popularity, but the open development platform that
developers love is also attractive to malware creators. Download this white
paper to learn more about secure code signing practices that can help keep
Android apps secure.
http://pubads.g.doubleclick.net/gampad/clk?id=65839951&iu=/4140/ostg.clktrk