Skip to content

Commit

Permalink
added threat model section
Browse files Browse the repository at this point in the history
  • Loading branch information
cameronvoell committed Dec 20, 2024
1 parent 42b3685 commit e6ae14e
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions XIPs/xip-48-content-type-local-db-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -317,6 +317,10 @@ No new security considerations are introduced with this XIP. The security consid

\* In the case of content types managed by the [XMTP GitHub organization](https://github.com/xmtp) the authority would be contributors/admins of the relevant GitHub repos.

### Threat model

As usual, users and developers should aspire to be using the latest XMTP SDK versions whenever possible, but you can never be sure whether inboxes you are chatting with on XMTP are using older or modified versions of the SDK. This means that users could configure their messages to specify that they are sending a certain content type, but the format, contents, or intentions of the actual data in the message could be something different. Fortunately, we haven't identified any security issues that would arise from this possibility, but it is something developers utilizing "complex decoding or presentation logic" as mentioned in the quote above, should be aware of. If any more specific threats or example of misuse arise, this section will be updated.

## Copyright

Copyright and related rights waived via [CC0](https://creativecommons.org/publicdomain/zero/1.0/).

0 comments on commit e6ae14e

Please sign in to comment.