4 ms·
Amazon solves this with shared keys, and is filepicker's up coming solution. You might want to look into doing it like that.
by Stealth- 14y ago
Amazon solves this with shared keys, and is filepicker's up coming solution. You might want to look into doing it like that.
- damncabbage 14y agoCould you elaborate on this, please? I can't find much on the topic. Edit: The Filepicker.io email seems to indicate a PKI-style solution, but I can only sort of guess at the implementation.
- adatta02 14y agoSure - check out http://aws.amazon.com/articles/1434 http://aws.amazon.com/articles/1434 What you're interested in is: "signature" - "A signature value that authorizes the form and proves that only you could have created it. This value is calculated by signing the Base64-encoded policy document with your AWS Secret Key, a process that I will demonstrate below."
- gliese1337 14y agoI may be missing something, but it seems to me that's still vulnerable to interception. The policy document can limit the kinds of things that can be uploaded, but an attacker could still intercept that form on the way to or from the user and replace the intended user's data with anything else that happened to fit the policy. I suppose that's solved by serving the form over https. Perhaps that's just what I was missing.
- adatta02 14y agoHTTPs would work but also if you scroll down a bit and look at the policy JSON (http://pastie.org/private/tkr7iyqzqrezmmqazbfijw http://pastie.org/private/tkr7iyqzqrezmmqazbfijw), it has an "expiration" field which would mitigate the type of attack outlined in the parent post since after a period of time the signature would no longer be valid.