~

On 10 May 2001, Mr.Bad wrote:

> >>>>> "BC" == Benjamin Coates <coates at windmail.net> writes:
> 
>     BC> Content-Type is how the client decides which viewer to pass
>     BC> the data on to.  Clients are unlikely to do anything at all
>     BC> with things like "Description" or "Publisher" or "Title".
>     BC> This is the sort of thing that would be useful *before* you
>     BC> download the CHK, like in an index or something, but putting
>     BC> it into the CHK itself means you have to download the whole
>     BC> file to get the subject (for example).
> 
> This is a fair point, but one of the principles that has been espoused
> here is that you -shouldn't- be able to get metadata about a data item
> without actually fetching the entire data item, since that makes
> certain kinds of attacks easier.
>

Thats irrelevant if the files are stored separately.  The issue with being
able to fetch part of a file without fetching the whole was so that a
malicious party could not locate the nodes storing certain material
without that material spreading.  
   Thats not an issue with the metadata stored separately from the data,
because the location of the metadata is in no way correlated to the
location of the data.

        Scott



_______________________________________________
Devl mailing list
Devl at freenetproject.org
http://lists.freenetproject.org/mailman/listinfo/devl

Reply via email to