biscuit icon indicating copy to clipboard operation
biscuit copied to clipboard

Clarify in docs if a snapshot is sensitive data

Open ahupp opened this issue 1 year ago • 2 comments

It's unclear from the docs; can a snapshot be turned back into a usable biscuit? I'm wondering about the contexts it would be safe to log it, and whether I need to attenuate with check if false; or something before doing so?

ahupp avatar Oct 07 '24 02:10 ahupp

Snapshots don’t contain sensitive cryptographic material, as they are built after signature verification. The only cryptographic material they contain is public keys from trusting annotations.

As such you cannot turn an authorizer into a usable biscuit without the signing private key.

As for logging, you still need to care about PII that might be contained in the biscuit or the authorizer, but that’s a separate concern.

divarvel avatar Oct 07 '24 12:10 divarvel

Stating this clearly in documentation would be a good idea indeed.

divarvel avatar Oct 07 '24 12:10 divarvel