Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reduce time information leakage of file uploads and file downloads #3305

Merged
merged 2 commits into from
May 1, 2018
Merged

Reduce time information leakage of file uploads and file downloads #3305

merged 2 commits into from
May 1, 2018

Conversation

evilaliv3
Copy link
Contributor

@evilaliv3 evilaliv3 commented Apr 25, 2018

The proposed fix together with the existing implementation performed for ticket #301 should be enough to avoid complete leakage of the file upload date.

Fixes #3304

@evilaliv3 evilaliv3 requested a review from a user April 25, 2018 12:33
@ghost ghost added app security labels Apr 25, 2018
@ghost ghost changed the title Address issue #3304 Reduce time information leakage of file uploads and file downloads Apr 25, 2018
Copy link
Contributor

@heartsucker heartsucker left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would it be possible to add an additional check to this that when we unzip and read the file back, we can check it's attribute to ensure that the time is actually set to 0?

@codecov-io
Copy link

Codecov Report

Merging #3305 into develop will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff            @@
##           develop    #3305   +/-   ##
========================================
  Coverage    85.76%   85.76%           
========================================
  Files           34       34           
  Lines         2157     2157           
  Branches       238      238           
========================================
  Hits          1850     1850           
  Misses         250      250           
  Partials        57       57

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 670c8ba...785ec32. Read the comment docs.

@evilaliv3
Copy link
Contributor Author

Yep @heartsucker, i agree.

Maybe a full retesting of the zip archive for both the single file and the bulk archive

@redshiftzero redshiftzero added this to the 0.7 milestone Apr 26, 2018
@redshiftzero redshiftzero requested a review from emkll April 26, 2018 19:34
Copy link
Contributor

@emkll emkll left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @evilaliv3 for the fix! Changes look good to me. I can confirm this strips the compression time on the submission's gzip archive.

On develop:

$ file 1-iridescent_cheapskate-doc.gz
1-iridescent_cheapskate-doc.gz: gzip compressed data, was "file.txt", last modified: Mon Apr 30 14:01:02 2018, max compression

On this branch:

securedrop$ file 1-infectious_carpentry-doc.gz
1-infectious_carpentry-doc.gz: gzip compressed data, was "file.txt", max compression

I agree with @heartsucker that adding a test to ensure the time is properly stripped is a good idea, but will defer to @redshiftzero on if this is required for merge.

@redshiftzero
Copy link
Contributor

Let's merge this and then add additional testing - both changes should get backported into 0.7.0

Copy link
Contributor

@emkll emkll left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I've created #3329 to implement at a later time. Thanks @evilaliv3 !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Reduce time information leakage of file uploads and file downloads
5 participants