Skip to content

Commit

Permalink
address @technosophos feedback
Browse files Browse the repository at this point in the history
Signed-off-by: Trishank K Kuppusamy <[email protected]>
  • Loading branch information
trishankatdatadog committed Jan 29, 2020
1 parent b4fe450 commit c9b00fc
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion 301-metadata-repositories.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,7 +145,7 @@ Table 1 presents a summary of possible attacks given the key compromise of one o
| timestamp + snapshot + targets (TUF) + step1 (in-toto) | Yes (limited by TUF root) | Yes | Yes | Yes |
| timestamp + snapshot + targets (TUF) + step2 (in-toto) | Yes (limited by TUF root) | Yes | Yes | Yes |

**Table 1**: The security attacks that are possible given the key compromise of one or more TUF role or in-toto functionary.
**Table 1**: The security attacks that are possible given the key compromise of one or more TUF role or in-toto functionary. Columns marked "Yes" indicate that the specified attack is possible _given_ the compromise of _all_ of the specified keys, whereas columns marked "No" indicate that they are not.

As Table 1 suggests, bundle developers SHOULD use offline keys to sign:

Expand Down

0 comments on commit c9b00fc

Please sign in to comment.