Sign update manifests so clients can reject a forged update #1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The problem
The server sends every manifest unsigned.
sendMultipartinapps/backend/src/routes/expo.tswrites the JSON body and no signature.An app trusts whatever answers its manifest request. If someone takes control of
the domain, the host, or the connection, that person can send their own
JavaScript bundle. The app runs it with the permissions of the real app.
TLS stops an attacker on the network. It does not stop an attacker who gets the
server or the DNS record.
What code signing adds
expo-updates supports a second layer. The build embeds a public certificate. The
server holds the private key and signs each manifest. The client checks the
signature before it loads the update, and rejects a manifest that does not match.
Then a stolen server alone is not enough. The attacker also needs the private key.
Work
expo-signatureheader.noUpdateAvailabledirective as well.Open questions
Expo ships
expo-updates codesigning:generateandexpo-updates codesigning:configurefor the client side. Confirm the flags against thecurrent Expo documentation before you write the guide.