Re: [atlas] contacing probe owner.
Quite the opposite IMHO, understanding that the anticipated means of communication will be email and that the email address of a probe's host will be generic, eg. <ripe-atlas-probe-[number]@atlas.ripe.net>, redirecting all incoming emails to a final address. The redirection would be configured via the portal then.
Using an address as described above would allow enumeration attacks. If it would use a hash instead it would be safer. The hash for probe XXX would be obtainable via the portal, where you would need to look up probe's details anyway. Geert Jan
Hi Geert Jan - On 20.04.2019 13:49, Geert Jan de Groot wrote:
Quite the opposite IMHO, understanding that the anticipated means of communication will be email and that the email address of a probe's host will be generic, eg. <ripe-atlas-probe-[number]@atlas.ripe.net>, redirecting all incoming emails to a final address. The redirection would be configured via the portal then.
Using an address as described above would allow enumeration attacks.
true. OTOH & as I wrote: I don't really care.
If it would use a hash instead it would be safer.
The hash for probe XXX would be obtainable via the portal, where you would need to look up probe's details anyway.
Do I? Always? I have attempted to deploy KISS here - but anyhow: I'd obviously also be fine with a more advanced (definition thereof) solution. Best, -C.
participants (2)
-
Carsten Schiefner
-
Geert Jan de Groot