Re: Sub/Not Security, Presence service identifiers
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
"Mark Day" <[email protected]> writes: > I guess I'm a little confused, then. In a previous message, I think with > respect to the same example, you wrote > > "Signing the presence information by the person that created it does > not fix the problem, because a spoofing presence service could collect > signed presence information and replay them in an order that > misinforms the watcher." > > I don't understand how this style of replay attack is viable if the presence > information signed by the creating principal includes a timestamp covered by > the signature. I'm afraid I don't know where I made this comment, however, the concern is that a spoofing presence service will give a watcher old information, even when updates are available. Since the content covered by the signature does not say when the notification operation was performed by presence service, a spoofing presence service can lie about the timeliness of the information, and the watch will never be the wiser for it. > Could you clarify whether you are concerned about a replay attack or > some other form of attack, and which parts of the system have to be > subverted for that attack to succeed? It would be helpful to me, at > least, for you to be very explicit about these points because some > things that may be obvious to you are not obvious to me. I hope I have answered these questions in other posts today. I attempted to clarify the example that demonstrates the value of having a presence service identifier. If I have not answered your questions, please ask again. John [reminder: [email protected] for non-technical discussions, please]