Skip to content

Commit 132f96a

Browse files
lukpuehJustinCapposjoshuagl
committed
Add details about ffwd attacker goals
Co-Authored-By: Justin Cappos <[email protected]> Co-Authored-By: Joshua Lock <[email protected]>
1 parent f50f522 commit 132f96a

File tree

1 file changed

+5
-2
lines changed

1 file changed

+5
-2
lines changed

tuf-spec.md

+5-2
Original file line numberDiff line numberDiff line change
@@ -1118,12 +1118,15 @@ repo](https://github.com/theupdateframework/specification/issues).
11181118

11191119
* **1.9**. **Fast-forward attack recovery** A _fast-forward attack_ happens
11201120
when attackers arbitrarily increase the version numbers in any of the
1121-
timestamp, snapshot, targets, or delegated targets metadata. To recover from
1121+
timestamp, snapshot, targets, or delegated targets metadata. The attacker goal
1122+
is to cause clients to refuse to update the metadata later because the attacker's
1123+
listed metadata version number (possibly MAX_INT) is greater than the new valid
1124+
version. To recover from
11221125
fast-forward attacks after the repository has been compromised and recovered,
11231126
certain metadata files need to be deleted as specified in this section.
11241127
Please see [the Mercury
11251128
paper](https://ssl.engineering.nyu.edu/papers/kuppusamy-mercury-usenix-2017.pdf)
1126-
for more details.
1129+
for more details on fast-forward attacks.
11271130

11281131
* **1.9.1**. **Targets recovery** If a threshold of targets keys have been
11291132
removed in the new trusted root metadata compared to the previous trusted

0 commit comments

Comments
 (0)