RE: On the need for presence service identifiers

Graham Klyne <[email protected]>
Newsgroups gmane.ietf.impp
Message-ID <[email protected]>
At 12:17 PM 8/21/02 -0400, Mark Day wrote:
> > Eve subscribes to both Alice's and Bob's presentity and saves Sunday's
> > version of their presence information.  On Monday, either by playing
> > with DNS or by intercepting traffic between alice.com and bob.com, Eve
> > sends Bob's old presence information to Alice, and Alice's old
> > information to Bob.  Because of this, all day Monday, Alice and Bob
> > think each other is offline, and fail to communicate.  Alice and Bob
> > have no way of knowing that the presence information they have is
> > stale.  This attack is foiled if notification content is timestamped
> > and signed when a notification operation is invoked.
>
>I think I understand this, and agree that it is a potential vulnerability. I
>disagree about its likely practical importance and the proposed solution.

I tend to agree.  I think a far simpler way to achieve the same effect, and 
which is not repaired by the proposed security features, is for an attacker 
to simply block delivery of notification messages.

[Catching up on the debate -- this is just a point response to what I 
perceive as a point issue.]

#g

-------------------
Graham Klyne
<[email protected]>



  [reminder: [email protected] for non-technical discussions, please]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.