Re: [w3c/push-api] Some questions about VAPID and encrypted messages (#278)

> In either scenario, yes, that would create any number of subscriptions with different applicationServerKey values. It's not defined how the push service stores this, but conceptually it's just a piece of metadata it stores with the subscription.

This creates a lot of subscriptions that is not actually used. I think, for hackers, this could be a chance to attack the push service.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/push-api/issues/278#issuecomment-315935081

Received on Tuesday, 18 July 2017 01:53:36 UTC