-
Notifications
You must be signed in to change notification settings - Fork 3
Description
Hi there!
Thanks for going through all this effort (to support some proprietary solution that doesn't support linux but is sometimes the only solution provided 😞 ).
Although I have an understanding of basic security principles, I feel like I don't fully grasp what the possible implications of following paragraph in the readme might be when I use this tool with a party that I otherwise trust.
There is also one security feature which is not implemented, because the algorithm is unknown. Whether this security through obscurity feature is really improving the security or not is debatable, but you should be aware that your personal data may be sent to anyone on the internet when using this application.
For the non-implemented feature, could you add some reference (to the relevant part in the implementation maybe) as to provide some context on where this is situated?
As to the "sent to anyone on the internet": what does this mean exactly? I understand that if you use this tool on a domain you don't trust, or if some payload sent contains sensitive info and is unencrypted that one could say "to anyone on the internet". Otherwise not so much 🤔 Could you please clarify?
Thanks again!
Michaël