Uploaded image for project: 'Realm Core'
  1. Realm Core
  2. RCORE-2138

Encryption key lifetime management improvements

    • Type: Icon: Epic Epic
    • Resolution: Unresolved
    • Priority: Icon: Unknown Unknown
    • None
    • Affects Version/s: None
    • Component/s: Core
    • None
    • Not Needed
    • Encryption key lifetime management improvements
    • None
    • None
    • 0
    • 4
    • 6
    • 100
    • Unknown
    • Hide

      >> THIS PROJECT REQUIRES STATUS UPDATE.
      _Last status:
      Engineer(s): Kirill Burtsev
      Last two weeks:
      * Getting the PR up to date with latest revision of core. Stuck on issue on old android devices (<= 10). Investigating.
      * Compiled for nodejs sdk, checking that it works. JS sdk copies the key when requested by the user, but it makes it impossible for core to zero the key bytes when it leaves its boundaries. This needs some discussion if it partially defeats the purpose of the proposed API change.
      * Overall, progress is slow due to vacation and other duties. 

      Next two weeks:
      * Fix Android issue, update the feature branch to the final state, discuss the API change with js sdk folks.

      Why did the end date change?
      * to accomodate planned time-off_

      REMOVE THIS SECTION WHEN THE PROJECT STATUS UPDATE IS COMPLETED<<

      Engineer(s): Kirill Burtsev
      Last two weeks:

      • ?

      Next two weeks:

      • ?

      Why did the end date change?

      • ?
      Show
      >> THIS PROJECT REQUIRES STATUS UPDATE. _Last status: Engineer(s): Kirill Burtsev Last two weeks: * Getting the PR up to date with latest revision of core. Stuck on issue on old android devices (<= 10). Investigating. * Compiled for nodejs sdk, checking that it works. JS sdk copies the key when requested by the user, but it makes it impossible for core to zero the key bytes when it leaves its boundaries. This needs some discussion if it partially defeats the purpose of the proposed API change. * Overall, progress is slow due to vacation and other duties.  Next two weeks: * Fix Android issue, update the feature branch to the final state, discuss the API change with js sdk folks. Why did the end date change? * to accomodate planned time-off_ REMOVE THIS SECTION WHEN THE PROJECT STATUS UPDATE IS COMPLETED<< Engineer(s): Kirill Burtsev Last two weeks: ? Next two weeks: ? Why did the end date change? ?

      Bosch wanted us to make sure an attacker can't easily dump a realm encryption key from memory while the realm is open.

            Assignee:
            kirill.burtsev@mongodb.com Kirill Burtsev (Inactive)
            Reporter:
            marysia.pietraszewska@mongodb.com Marysia Pietraszewska (Inactive)
            None
            AD Sync Client
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:

                Estimated:
                Original Estimate - 0 minutes
                0m
                Remaining:
                Remaining Estimate - 2 weeks
                2w
                Logged:
                Time Spent - Not Specified
                Not Specified