Re: IQ Handling vulnerabilities

"Joe Hildebrand (jhildebr)" <[email protected]>
Newsgroups gmane.ietf.xmpp
Message-ID <[email protected]>
I have a couple of ludicrous s2s attacks on mind, but more important I think is doing what

Mobile/terse. DYAC.

On Feb 7, 2014, at 7:50 AM, "Dave Cridland" <[email protected]<mailto:[email protected]>> wrote:

On Fri, Feb 7, 2014 at 3:10 PM, Joe Hildebrand (jhildebr) <[email protected]<mailto:[email protected]>> wrote:
On 2/7/14 2:46 AM, "Thijs Alkemade" <[email protected]<mailto:[email protected]>> wrote:

>The property we really want from ids is that predicting the next one(s)
>given
>some historic ones is hard.

(as individual)

I agree with everything you said to this point.  However, I think we need
to strengthen this a little: we want to ensure predicting the next one(s)
in *any* way is hard.

Luckily using the from address also mitigates this need slightly for some
of the use cases.

What are the attacks possible against an entity using predictable stanza ids, but which otherwise acts properly (ie, checks to/from on responses, etc)?

I'm a bit confused - if an entity isn't checking the to/from of the responses, then sure there's a slew of attacks possible. If it *also* has predictable ids, then the attacks are easier - but they're the same attacks. Aren't they?

I'm not saying that we shouldn't generally recommend unpredictable ids - it seems relatively simple and causes little harm - but cryptographically secure ones seems overkill, and I'm always nervous of imposing unneeded drains on the entropy store of a system.

Also, I've mentioned this elsewhere, but I'll mention it here too: much of the XMPP community seems focussed on clients exhibiting this class of bug, and attacks against those clients. I strongly suspect that not all servers are immune to this, and the attacks on servers are likely to be just as fascinating.

Dave.

_______________________________________________
xmpp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/xmpp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.