Threat Analysis: Remote Login Propagation
See also blog: geballte sicherheit for getting an idea about the analysis.
Technical Background
Control Flow
Data transferred
Data Flow
Analysis
Assets
- Service Availability: The availability of our or foreign servers.
- Instance Reputation: We hope our project does not live on a spam instance.
- Project Reputation: The reputation of an individual project.
Actors
- Script Kiddies: Boored teens, willing to do some illegal stuff without deep knowledge of tech details but broad knowledge across internet discussions. Able to do some bash / python scripting.
- Experienced Hacker: Hacker with deep knowledge.
- Hacker: Hacker with some knowledge.
- Malicious Fediverse Member: Malicious Members of the fediverse, able to operate malicious forge instances.
- Malicious Forge Admin: Admin of good reputation forge instance in the fediverse.
- Federated User: Members of good reputation forge instance in the fediverse.
Threat
- tbd
Mitigations
- tbd
DREAD-Score
Threat | Damage | Reproducibility | Exploitability | Affected Users | Discoverability | Mitigations |
---|---|---|---|---|---|---|
1. | … tbd | |||||
2. | … tbd |
Threat Score with values between 1 - 6
- Damage – how severe would the damage be if the attack is successful? 6 is a very bad damage.
- Reproducibility – how easy would the attack be reproducible? 6 is very easy to reproduce.
- Exploitability – How much time, effort and experience are necessary to exploit the threat? 6 is very easy to make.
- Affected Users – if a threat were exploited, how many percentage of users would be affected?
- Discoverability – How easy can an attack be discovered? Does the attacker have to expect prosecution? 6 is very hard to discover / is not illegal