Skip to content

Conversation

@DHerls
Copy link

@DHerls DHerls commented Feb 12, 2024

smbj by default does not require message signing and does not encrypt data. This could lead to program authors inadvertently writing insecure software.

The library should have secure defaults and allow users to reduce their security if they need.

@DHerls DHerls requested a review from hierynomus as a code owner February 12, 2024 16:11
@hierynomus
Copy link
Owner

With these settings you'll also need to remove the supported dialects for SMB2. The goal of the default config is to make it more compatible. I would welcome a second "default setup" which is more secure.

So adding a createSecureConfig()

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants