Bug#975695: please allow to use UUIDs for "paste numbers"

2021-02-09 Thread Tomas Pospisek

Cool, thanks (-: <3 !
*t

On Mon, 8 Feb 2021, Patrick Matthäi wrote:


Hi

Am 25.11.20 um 09:54 schrieb Tomas Pospisek:

Source: pnopaste
Version: 1.7.4
Severity: wishlist

Having "pastes" with monotonically increasing numbers allows an
"attacker" to discover all pastes by simply counting through
them from 0 on.

Assigning UUIDs to pastes would make that computationally
impossible.

Something like http://nopaste.linux-dev.org/?jA7vBQ8927 or such.

*t

first thanks for your other patch. I support this idea and I will implement 
it with the next release, which also gets backports then.


But first I have release and uploaded today version 1.8 with a small 
adjustment for pnopaste-cli, so that this client supports in the future also 
UUID paste numbers.







Bug#975695: please allow to use UUIDs for "paste numbers"

2021-02-08 Thread Patrick Matthäi

Hi

Am 25.11.20 um 09:54 schrieb Tomas Pospisek:

Source: pnopaste
Version: 1.7.4
Severity: wishlist

Having "pastes" with monotonically increasing numbers allows an
"attacker" to discover all pastes by simply counting through
them from 0 on.

Assigning UUIDs to pastes would make that computationally
impossible.

Something like http://nopaste.linux-dev.org/?jA7vBQ8927 or such.

*t

first thanks for your other patch. I support this idea and I will 
implement it with the next release, which also gets backports then.


But first I have release and uploaded today version 1.8 with a small 
adjustment for pnopaste-cli, so that this client supports in the future 
also UUID paste numbers.




Bug#975695: please allow to use UUIDs for "paste numbers"

2020-11-25 Thread Tomas Pospisek
Source: pnopaste
Version: 1.7.4
Severity: wishlist

Having "pastes" with monotonically increasing numbers allows an
"attacker" to discover all pastes by simply counting through
them from 0 on.

Assigning UUIDs to pastes would make that computationally
impossible.

Something like http://nopaste.linux-dev.org/?jA7vBQ8927 or such.

*t


-- System Information:
Debian Release: 10.6
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.19.0-12-amd64 (SMP w/8 CPU cores)
Locale: LANG=de_CH.utf8, LC_CTYPE=de_CH.utf8 (charmap=UTF-8), LANGUAGE=de_CH:de 
(charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled