Re: IQ Handling vulnerabilities
Dave Cridland <[email protected]>
| Newsgroups | gmane.ietf.xmpp |
|---|---|
| Message-ID | <CAKHUCzzhxKLbkNE=WjtP9S6XWm14-5e7Ut150x4k1akegm+1Qw@mail.gmail.com> |
On Tue, Feb 11, 2014 at 12:23 PM, Alexander Holler <[email protected]>wrote: > Hmm, in all these mails it was never be mentioned that IDs still have to > be unique over some time for one session. I'm not sure if such is given > with the above constructs. It might be very unlikely that the same ID will > appear twice, but someone has to take a deeper look at it when using such > constructs like above. Of course, in reality the window in time IDs must be > unique is rather small, but ... > You'd need random collisions amongst cryptographically secure hashes. You're pretty safe. In practise, ids do not have to be unique anyway, even over a small window. Most MUC implementations preserve ids on broadcast, for instance, to no ill-effect. Dave. _______________________________________________ xmpp mailing list [email protected] https://www.ietf.org/mailman/listinfo/xmpp