asheesh changed the topic of #sandstorm to: Welcome to #sandstorm: home of all things sandstorm.io. Say hi! | Channel glossary: "i,i" means "I have no point, I just want to say". b == thumbs up. | Public logs at https://botbot.me/freenode/sandstorm/ & http://logbot.g0v.tw/channel/sandstorm/today
ArcTanSusan has quit [Quit: ArcTanSusan]
dograt has joined #sandstorm
|jemc| has quit [Ping timeout: 260 seconds]
ArcTanSusan has joined #sandstorm
ArcTanSusan has quit [Client Quit]
|jemc| has joined #sandstorm
heliostatic has quit [Ping timeout: 260 seconds]
ArcTanSusan has joined #sandstorm
heliostatic has joined #sandstorm
dograt has quit [Quit: Leaving]
heliostatic has quit [Ping timeout: 264 seconds]
ArcTanSusan has quit [Quit: ArcTanSusan]
dograt has joined #sandstorm
heliostatic has joined #sandstorm
ArcTanSusan has joined #sandstorm
ArcTanSusan has quit [Client Quit]
ArcTanSusan has joined #sandstorm
ArcTanSusan has quit [Client Quit]
dograt has quit [Quit: Leaving]
|jemc| has quit [Quit: WeeChat 1.2]
|jemc| has joined #sandstorm
ArcTanSusan has joined #sandstorm
ArcTanSusan has quit [Quit: ArcTanSusan]
ArcTanSusan has joined #sandstorm
ArcTanSusan has quit [Quit: ArcTanSusan]
heliostatic has quit [Ping timeout: 240 seconds]
|jemc| has quit [Ping timeout: 255 seconds]
heliostatic has joined #sandstorm
heliostatic has quit [Ping timeout: 250 seconds]
heliostatic has joined #sandstorm
xet7 has quit [Ping timeout: 240 seconds]
amyers has joined #sandstorm
amyers has quit [Read error: Connection reset by peer]
amyers has joined #sandstorm
amyers has quit [Read error: Connection reset by peer]
amyers has joined #sandstorm
amyers has quit [Read error: Connection reset by peer]
mnutt has joined #sandstorm
fonfon has joined #sandstorm
fonfon has quit [Remote host closed the connection]
fonfon has joined #sandstorm
heliostatic has quit [Ping timeout: 255 seconds]
ArcTanSusan has joined #sandstorm
|jemc| has joined #sandstorm
fonfon has quit [Ping timeout: 255 seconds]
heliostatic has joined #sandstorm
fonfon has joined #sandstorm
mnutt has quit [Quit: mnutt]
ArcTanSusan has quit [Quit: ArcTanSusan]
mnutt has joined #sandstorm
tobald has joined #sandstorm
mnutt has quit [Quit: mnutt]
mnutt has joined #sandstorm
tobald has quit [Ping timeout: 246 seconds]
fonfon has quit [Remote host closed the connection]
fonfon has joined #sandstorm
decipherstatic has joined #sandstorm
mnutt has quit [Quit: mnutt]
xet7 has joined #sandstorm
mnutt has joined #sandstorm
xet7 has quit [Client Quit]
xet7 has joined #sandstorm
ArcTanSusan has joined #sandstorm
ArcTanSusan has quit [Client Quit]
ArcTanSusan has joined #sandstorm
ArcTanSusan has quit [Quit: ArcTanSusan]
heliostatic has quit [Ping timeout: 240 seconds]
mnutt has quit [Quit: mnutt]
heliostatic has joined #sandstorm
fonfon has quit [Remote host closed the connection]
mnutt has joined #sandstorm
heliostatic has quit [Ping timeout: 272 seconds]
paroneayea has quit [Ping timeout: 240 seconds]
mnutt has quit [Quit: mnutt]
heliostatic has joined #sandstorm
ArcTanSusan has joined #sandstorm
<maurer> In URLs, is the url implicitly "secret"?
<maurer> err, in grain URLs rather
<maurer> I'm wondering whether or not you get CSRF protection "for free" in https'd, non-proxy'd sandstorm
<maurer> (basically I'm wondering whether the grain ID is a capability identifier, and so there is a different one for each privilege level, or if it is just a site identifier, and so any user on the site would have the grain id)
<dwrensha> the grain ID is not a secret, and is the same for every user
<dwrensha> each session gets a different host
<maurer> Hm.
<maurer> I guess the separate host _should_ make the form urls secret?
<maurer> basically I'm trying to figure out if there's a way to use the fact that sandstorm is capability oriented to dodge csrf reqs
<dwrensha> if someone can eavesdrop on your DNS requests, you still might be in trouble
<maurer> Hm, that's true
<maurer> And DNS is not generally secured
<maurer> a shame it couldn't be in the url somewhere instead :/
<maurer> (or maybe a separate secret in the URL)
<maurer> that seems like it'd provide significant additional XSRF mitigation in the event that SSL was available
<maurer> (the url thing there just being another separate, similarly lengthed session token)
mnutt has joined #sandstorm
paroneayea has joined #sandstorm
mnutt has quit [Quit: mnutt]
dwrensha_ has joined #sandstorm
ripdog_ has joined #sandstorm
hunterm___ has joined #sandstorm
ocdtrekkie_ has quit [Quit: No Ping reply in 180 seconds.]
garrison has quit [Ping timeout: 250 seconds]
sprin_ has joined #sandstorm
uppermgmt_ has joined #sandstorm
azirbel_ has joined #sandstorm
ocdtrekkie has joined #sandstorm