[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Uri-review] ssh URI



On 10/13/09 6:02 AM, David Booth wrote:
Getting a scheme registered is the *easy* part.  The hard part is
getting millions of installed clients to implement the special
recognition of that scheme.

I agree, and I think what you're proposing is interesting along those lines. I also appreciate your answers to my earlier questions. Right now we have no guidance or analysis that goes into the associated risks of what you are proposing. A few examples of things that can and will go wrong with non-participants:

1. A query goes out to a third party, and the site is down or unreachable. In this case, the non-participant will hang in an unspecified way rather than get a hard error. 2. A query goes out and the third party has been compromised. And in this case, the third party is a really attractive target because one can map administrative resources with SSH. Worse, the client acts on the meta-information in some way, leading to additional compromises. You're already using redirects. So what can a bad guy redirect to in order to make things interesting? Well, he's got a Browser: header. Perhaps he redirects to an appropriate exploit.

Now to be fair to you, I haven't done the analysis to say, "this is ABSOLUTELY a problem", but nor have I seen an analysis from you that leads me to conclude that this is not a problem.

Eliot