Repository navigation
Conversation
Contributor
|
Thanks for your interest in contributing. Per our SECURITY.md and CONTRIBUTING.md, security reports should be directed to security@signal.org rather than on Github. If you've already written in and haven't yet received a reply, please know we're looking into it! Thanks again, and as always for being a Signal user. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Contributor checklist
Administrative:
Commits and testing:
Description
The logging api calls have a regex to filter sensitive info like email addresses, phone numbers and other stuff that shouldn't be stored. ideally apple provides the proper private logging apis that redact all that using swift primitives.
Using a regex may somehow work but the current implementation is not covering all possible cases, and in this case there's a root key logged and it's bypassing the regex checks. And also absolute paths can be used as a reference for other exploits to pivot the app home directory if the attacker have access to the logs.
Ideally none of this information should be exposed in the logs, no matter if its usb, icloud or device backups. So my proposed solution is to catch those absolute paths in the regex, and just don't log the root key.
Feel free to pick those commits with tests to proof the regex cornercase or just adjust the patch the way it works better for you, no need for mentions/merits/cves from my side. I just want to raise aware of these issues and being solved upstream asap.
thanks