You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules that we apply to check whether things aren't valid. Too loose, we risk spoofing - too tight, we risk DoS (perhaps)
A main question: should you reject stuff which is included in a transaction from a server, but isn't originally from that server, and is invalid? Answer: probably. However you need to check you can't engineer a state where a malicious server encourages a legitimate server to accept an invalid message.
matrixbot
changed the title
We need to define the validation rules applied to federation events.
We need to define the validation rules applied to federation events. (SPEC-27)
Oct 31, 2016
matrixbot
added
the
feature
Suggestion for a significant extension which needs considerable consideration
label
Nov 7, 2016
My notes from talking to Mjark yesterday:
A main question: should you reject stuff which is included in a transaction from a server, but isn't originally from that server, and is invalid? Answer: probably. However you need to check you can't engineer a state where a malicious server encourages a legitimate server to accept an invalid message.
(Imported from https://matrix.org/jira/browse/SPEC-27)
(Reported by @ara4n)
The text was updated successfully, but these errors were encountered: