~yujiri/sufec#24: 
TOFU

Currently transport-layer encryption is implemented but the client/lib blindly accepts the server's certificate.

Status
REPORTED
Submitter
~yujiri
Assigned to
No-one
Submitted
2 years ago
Updated
2 years ago
Labels
android

~yujiri 2 years ago

Update: a basic take on TOFU is in that just throws an error, but realistically there needs to be a way for the user to decide what to do.

~yujiri 2 years ago

Same thing is in the GTK client, nothing is yet in android.

~yujiri 2 years ago

reducing the scope of this issue to just be about TOFU existing at all, since #22 exists.

Register here or Log in to comment, or comment via email.