-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
Security Considerations (Section 7) states: "This document should not affect the security of the Internet." This is inadequate for a Standards Track document. Message Keys expose structural information about the operator's YANG schema deployments and hostname conventions to anyone with access to the Message Broker. The security section should at minimum discuss: (a) Message Broker access control to prevent information leakage via topic names and Message Keys; (b) the risk of Message Key collision attacks degrading partitioning uniformity; and (c) alignment with the security considerations of the referenced RFCs (RFC 8641 §7 discusses access control for push updates in detail).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels