-
Notifications
You must be signed in to change notification settings - Fork 115
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Strengthen secure module language around keying material & add security note #2333
Conversation
Is this basically a note about the problem outlined at web-platform-tests/wpt#19572 (comment)? That aside from serializing and deserializing we also need to have a hook when a serialization is about to cross a boundary? |
Ping! This has been inactive for a while |
Updated prose to more explicitly suggest some form of secure module indirection (preferably a separate process, though I doubt we can do any stronger than SHOULD on that since some implementations may not have multiple processes). @annevk does this look good to you? (sorry I'm not able to parse your last question in this thread). I based this off your comment in #2343 (comment). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yeah, this looks good to me, thanks! (The question here isn't relevant anymore as the confidential data can be kept separate from the object itself.)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I have read through this version, I believe I understand it, and I approve of it as written.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'm not an expert on this, but LGTM as far as I'm concerned.
Fixes #2343. (Updated. Previous description:)
From TPAC decision, add security note for #2257. cc @annevk
Preview | Diff