Homestyx hydra

R1:63828f580689

Store and verify content integrity checksums for files

Summary:
Ref T12470. This helps defuse attacks where an adversary can directly take control of whatever storage engine files are being stored in and change data there. These attacks would require a significant level of access.

Such attackers could potentially attack ranges of AES-256-CBC encrypted files by using Phabricator as a decryption oracle if they were also able to compromise a Phabricator account with read access to the files.

By storing a…
Repository: R1 hydra
Commit Date: Apr 5 2017