Skip to content

Attack consequence: data exfiltration #24

@jg10-mastodon-social

Description

@jg10-mastodon-social

In various venues, the question has come up a number of times of whether and how Solid prevents apps from using data for unintended uses, notably exfiltrating data in a way that then allows arbitrary access for any use.

I've titled this as an attack consequence because it's currently trivial - any app authorized to read data can exfiltrate it. However, it is still something we don't want, and it is something that might be mitigated in future.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions