Issue 220 - Recommended trust hook is insecure (monotone)

[email protected]
Newsgroups gmane.comp.version-control.monotone.devel
Message-ID <bcd07a49c47435887c91a553f2074169@localhost>
Hello,

A new issue has been created:

220 - Recommended trust hook is insecure
Project: monotone
Status: New
Reported by: joe 23
Labels:
 Type:Defect
 Priority:Medium

Description:

... and no documentation on how to fix it.

The docs at http://www.monotone.ca/docs/Trust-Evaluation-Hooks.html recommend a key name based get_revision_cert_trust hook but that is insecure since monotone now allows duplicate key names.

A secure implementation must use the key ID, but there's no documentation on how to do that. The secure hook may be implemented by using quoted hex key ids in 'trusted_signers", and implementing a new function (e.g. 'idintersection') that uses v.id instead of v.name.

This ticket is for a fix to the website and any other places where the example is given, to provide a secure example.



Steps to reproduce the problem:
-------------------------------

1. Add second key with same name
2. Sample trust hook will trust it too


Expected result:
----------------
Better example


Output of `mtn version --full`:
-------------------------------
1.0.0

--
Issue: https://code.monotone.ca/p/monotone/issues/220/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.