From 306b3f5d629fa0b38d028098d6825e437180dc0d Mon Sep 17 00:00:00 2001 From: Florian Jacob Date: Mon, 20 Nov 2017 13:36:05 +0100 Subject: [PATCH 1/2] =?UTF-8?q?Threat=20Model:=20Align=20indentation=20of?= =?UTF-8?q?=20Spying=20Threats.=20=E2=80=9CDisclosure=20to=20Servers=20Wit?= =?UTF-8?q?hin=20Chatroom=E2=80=9D=20was=20indented=20lesser=20than=20the?= =?UTF-8?q?=20surrounding=20threats.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Florian Jacob --- specification/appendices/threat_model.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/specification/appendices/threat_model.rst b/specification/appendices/threat_model.rst index 0dea62e01..a25b98797 100644 --- a/specification/appendices/threat_model.rst +++ b/specification/appendices/threat_model.rst @@ -134,7 +134,7 @@ An attacker could try to convince servers within a chatroom to send messages to a server it controls that was not authorised to be within the chatroom. Threat: Disclosure to Servers Within Chatroom -~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ++++++++++++++++++++++++++++++++++++++++++++++ An attacker could take control of a server within a chatroom to expose message contents or metadata for messages in that room. From a0455eb5b1730bd0d682130565552de4b4a0301f Mon Sep 17 00:00:00 2001 From: Florian Jacob Date: Mon, 20 Nov 2017 13:39:40 +0100 Subject: [PATCH 2/2] Threat Model: Wrong word: Banning users is a threat only if you're not authorized Signed-off-by: Florian Jacob --- specification/appendices/threat_model.rst | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/specification/appendices/threat_model.rst b/specification/appendices/threat_model.rst index a25b98797..9ad5fef80 100644 --- a/specification/appendices/threat_model.rst +++ b/specification/appendices/threat_model.rst @@ -65,7 +65,7 @@ making the chatroom unusable. Threat: Banning users without necessary authorisation +++++++++++++++++++++++++++++++++++++++++++++++++++++ -An attacker could attempt to ban a user from a chatroom with the necessary +An attacker could attempt to ban a user from a chatroom without the necessary authorisation. Spoofing