You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Creating another issue to track the security bug (data leak) that is a consequence of #193.
When using plugins/docker for builds, the internal docker setup sends DNS requests from the build unencrypted to Google's DNS servers at 8.8.8.8 and 8.8.4.4. This is a security bug, as it tells your ISP and anyone else listening what hostnames you are looking up!
The text was updated successfully, but these errors were encountered:
sneak
changed the title
Security Issue: plugin leaks hostnames unencrypted to WAN
Security Issue: plugin leaks hostnames unencrypted to 3P/WAN
Feb 12, 2020
Creating another issue to track the security bug (data leak) that is a consequence of #193.
When using plugins/docker for builds, the internal docker setup sends DNS requests from the build unencrypted to Google's DNS servers at
8.8.8.8
and8.8.4.4
. This is a security bug, as it tells your ISP and anyone else listening what hostnames you are looking up!The text was updated successfully, but these errors were encountered: