Re: On the need for presence service identifiers

[email protected] (John D. Ramsdell)
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
This proposal has some interesting properties, but I don't understand
how presence information is refreshed.  Suppose the standard lease
duration is one hour, and the person that owns the presentity goes
away for a week.  That person can no longer sign presence information
updates.  The alternative is that the presence service signs the
messages, but your note suggests you do not intend this.  Who signs
presence information when the person is away?

John

"Mark Day" <[email protected]> writes:

> I think I understand this, and agree that it is a potential vulnerability. I
> disagree about its likely practical importance and the proposed solution.
> 
> If I were particularly concerned about foiling this attack, I would change
> the timestamps in the presence information to leases -- they would have a
> start-time and an end-time, or a start-time and a duration. The presentity
> could choose the length of lease so as to trade off the interval during
> which this attack is possible vs. the inconvenience of refreshing
> otherwise-unchanged presence information whose lease has expired.
> 
> I believe this approach would solve the identified problem without the need
> to introduce the machinery to name, authenticate, etc. etc. the presence
> services and individual notifications.  But I may have overlooked something,
> so I'd welcome correction.



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.