Skip to content

Add admin signature validation in RsGenExchange#284

Open
zapek wants to merge 1 commit intoRetroShare:masterfrom
zapek:group-admin-signature-validation-fix
Open

Add admin signature validation in RsGenExchange#284
zapek wants to merge 1 commit intoRetroShare:masterfrom
zapek:group-admin-signature-validation-fix

Conversation

@zapek
Copy link
Copy Markdown
Contributor

@zapek zapek commented Apr 12, 2026

It is possible to fool Retroshare into accepting a group without verification by creating one that has no signature at all (no admin signature and no author signature).

Now it will check the admin signature for every new group, not just group updates.

It is possible to fool Retroshare into accepting a group without verification by creating one that has no signature at all (no admin signature and no author signature).

Now it will check the admin signature for every new group, not just group updates.
@zapek
Copy link
Copy Markdown
Contributor Author

zapek commented Apr 12, 2026

Maybe it's possible to write a common function with updateValid(), although they differ slightly. I did test my fix by modifying Xeres to send unsigned groups.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant