#evil zig mirror

1 messages · Page 1 of 1 (latest)

vagrant karma
#

there's no easy way to test that zig mirror downloaders are properly validating signatures and trusted comments. there should be an evil mirror server (either hosted, or just a binary you can run locally) that will do things like:

  • modifying the tarball and/or minisig file, to ensure the signature is actually being validated
  • replacing the requested version with a different version (along with the matching minisig) to ensure the trusted comment is properly checked against the requested filename
  • anything else that's evil and sneaky, eg. maybe DOS attacks like sending data r e a l l y s l o w l y to try and waste clients' time. that sort of thing should probably be opt-in though
vagrant karma
#

could also do non-security testing stuff, like ensuring the mirror list is randomized, ensuring a ?source= parameter is passed, ensuring the implementation tries the next mirror if there's an error, etc

hot mantle
vagrant karma
blazing gale
dapper yacht
daring locust
#

I’m willing to try this

mortal pawn
#

I started working on a (non-evil) Zig mirror using Go, but my work on it kind of petered out. Adding an evil-mode to it would probably not be too difficult

daring locust
#

omg I completely forgot about this

blazing gale
novel kayak
#

deploy zig version that instead of building your program, builds a terminal app that makes an ascii zig logo fly by and says "your downloader failed the vibe check! report a bug to their repo and stop using it until it's fixed!"

daring locust
#

hey I have been reminded of this again

mortal pawn
#

(Like sl)