5 ms·
Would this allow some kind of mine-by-SHA cross-site attacks? (sidenote: I've not thought this through, this is just an off-the-cuff thought.)
by Jailbird 14y ago
Would this allow some kind of mine-by-SHA cross-site attacks?
(sidenote: I've not thought this through, this is just an off-the-cuff thought.)
- alexchamberlain 14y agoIf you could find a malicious file that had the same hash as the current jQuery before the next one was released, then yes. I don't think this is possible, but I'm no expert!
- Jailbird 14y agoI guess I was thinking it'd be used for much more than just jQuery, and fast. Then for anything that any site wanted cached, some other site could essentially grab it if all they had was the hash.
- alexchamberlain 14y agoNot sure I understand. How would another site grab it? And if they imported it into their page, why would that matter?
- saalweachter 14y agoIf I'm reading it correctly, I think the idea is, imagine your bank uses a hash-cache of an AJAX request containing your bank statements (stupid, yeah, but everyone is stupid sometimes). A malicious website could then include a request to download a bogus URL from their site with a hash which matched that of the bank statement AJAX response. The browser would then return the cached bank statement, without ever noticing the URLs were bogus or didn't even point to a file with the desired hash. The malicious website could then upload the bank statements back to itself. This seems like technically an attack path, but it relies on being able to guess a 256-bit hash in a relatively small number of guesses; if you can do that, you might as well just start guessing password hashes and log in to a target website directly.
- RyanMcGreal 14y ago"If you fear SHA-256 collisions but do not keep with you a loaded shotgun at all times, then you are getting your priorities wrong." http://stackoverflow.com/a/4681221 http://stackoverflow.com/a/4681221
- jefffoster 14y agoI think that quote is appropriate if you fear collisions with your own data set. The worry with a cache scheme like this is people would be actively seeking to find cache collisions.
- alexchamberlain 14y agoThat answer clearly explains why you can't, using current techniques and hardware.
- Dylan16807 14y ago> current techniques We're talking about a long-term standard.
- sp332 14y agoDropbox used to be vulnerable to this because of their back-end deduplication. Users could know if a file had been uploaded already by seeing if the dropbox client had to upload it, or if the service "recognized" the hash. http://paranoia.dubfire.net/2011/04/how-dropbox-sacrifices-user-privacy-for.html http://paranoia.dubfire.net/2011/04/how-dropbox-sacrifices-u... Actually an FTC complaint was filed and Dropbox had to give a up a few of the benefits of deduplication.