Comment 5 for bug 1186867

Revision history for this message
Jeremy Stanley (fungi) wrote :

Can Nova developers comment specifically in here on what the actual intent is with network restrictions, whether it's just meant to limit access to particular networks or if it's really designed to hide all information on the unavailable topology and failing at that task? If the former, this seems like maybe a need for clearer wording in the documentation to set appropriate expectations along with a hardening feature request. If the latter, then I agree this is an information leak vulnerability (but a low one, because relying on the secrecy of your network topology to protect you from an attacker is a serious case of security by obscurity in my opinion).