Skip to content

Add some security considerations for sites using this API #38

@jyasskin

Description

@jyasskin

There's a nice paper at https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1C-3_23159_paper.pdf showing how server-side contact discovery APIs can be abused. The exploits don't directly attack this API, but developers using this API need to know that they should defend against them. A security considerations section in this spec seems like a good place to warn people.

Metadata

Metadata

Assignees

No one assigned

    Labels

    security-needs-resolutionIssue the security Group has raised and looks for a response on.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions