epub provides no authenticity or integrity checks · Issue #2265 · w3c/epub-specs · GitHub
Skip to content

epub provides no authenticity or integrity checks #2265

Open
@npdoty

Description

In the short term, the threat model should note the possibility that epub files are altered between the author and the reader, or that a book is distributed claiming to be the authentic work of someone else but with no feasible way to verify it.

In the long term, epub should use package-wide signatures (or some other mechanism) to provide at least the option for authenticity and integrity via PKI.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Spec-ReadingSystemsThe issue affects the EPUB Reading Systems 3.3 RecommendationStatus-DeferredThe issue has been deferred to another revisionsecurity-trackerGroup bringing to attention of security, or tracked by the security Group but not needing response.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions