Re: IQ Handling vulnerabilities

Dave Cridland <[email protected]>
Newsgroups gmane.ietf.xmpp
Message-ID <CAKHUCzzhxKLbkNE=WjtP9S6XWm14-5e7Ut150x4k1akegm+1Qw@mail.gmail.com>
On Tue, Feb 11, 2014 at 12:23 PM, Alexander Holler <[email protected]>wrote:

> Hmm, in all these mails it was never be mentioned that IDs still have to
> be unique over some time for one session. I'm not sure if such is given
> with the above constructs. It might be very unlikely that the same ID will
> appear twice, but someone has to take a deeper look at it when using such
> constructs like above. Of course, in reality the window in time IDs must be
> unique is rather small, but ...
>

You'd need random collisions amongst cryptographically secure hashes.
You're pretty safe.

In practise, ids do not have to be unique anyway, even over a small window.
Most MUC implementations preserve ids on broadcast, for instance, to no
ill-effect.

Dave.

_______________________________________________
xmpp mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/xmpp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.