RE: Sub/Not Security, Presence service identifiers
"Mark Day" <[email protected]>
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
> http://www.imppwg.org/ml-archive/IMPP-WG/200208/msg00003.html > > The purpose of the example is to demonstrate a situation in which it > is important that a presence service has an identifier that > distinguishes it as a presences service. In that example, a bad guy > that is not approved to behave as a presence service, is fabricating > presence information in an effort to spoof a watcher into using the > wrong inbox for instant messaging. Since the bad guy is creating > presence information and signing it, timestamping will not foil this > attack. I guess I'm a little confused, then. In a previous message, I think with respect to the same example, you wrote "Signing the presence information by the person that created it does not fix the problem, because a spoofing presence service could collect signed presence information and replay them in an order that misinforms the watcher." I don't understand how this style of replay attack is viable if the presence information signed by the creating principal includes a timestamp covered by the signature. Could you clarify whether you are concerned about a replay attack or some other form of attack, and which parts of the system have to be subverted for that attack to succeed? It would be helpful to me, at least, for you to be very explicit about these points because some things that may be obvious to you are not obvious to me. --Mark [reminder: [email protected] for non-technical discussions, please]