Skip to content

Spike: Investigate Thumbnail Poisoning #226

@jgrim

Description

@jgrim

Investigate how we can mitigate thumbnail poisoning.

How the thumbnail get poisoned:

  1. User uploads a link ( A "Cat" for example )
  2. Server caches it.
  3. User changes it to a banana ( or anything WORSE )
  4. Another user sees the cat in the thumbnail, clicks on it and sees a banana instead

Ideas of mitigating it:

Saving the thumbnail hash and let the frontend warn if the hash doesnt match anymore.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

Status

📋 Backlog

Relationships

None yet

Development

No branches or pull requests

Issue actions