Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

make sensitive operator actions auditable #1443

Closed
slingamn opened this issue Dec 7, 2020 · 0 comments
Closed

make sensitive operator actions auditable #1443

slingamn opened this issue Dec 7, 2020 · 0 comments
Labels
Milestone

Comments

@slingamn
Copy link
Member

slingamn commented Dec 7, 2020

@mogad0n points out that an operator can use /NS PASSWD to read DMs, or exploit a different operator's credentials.

There's no real remedy for this: accreg and chanreg are the biggest hammers in the toolbox. But we can improve accountability for this by sending a snomask and logging a line for each such action.

@slingamn slingamn added this to the v2.5 milestone Dec 7, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant