3 ms·
I've never used Snapchat but I believe one of its features is time-expiring photos. If they do the expiration in the client then this may be a way to check if a
by brainfire 10y ago
I've never used Snapchat but I believe one of its features is time-expiring photos. If they do the expiration in the client then this may be a way to check if a user is getting around it by setting the system clock backwards.
- jrockway 10y agoNTP doesn't cryptographically verify the time. All you do is have your router redirect these NTP requests to your own server, which is set to serve the wrong time. Ironically, part of an HTTPS handshake involves sharing the server time in a cryptographically-verifiable manner. I am not sure why they don't use that! https://github.com/ioerror/tlsdate https://github.com/ioerror/tlsdate
- brainfire 10y agoWell, I didn't say it was a good way ;)
- viraptor 10y agoThat only works for current TLS. Version 1.3 makes sending the server date optional.
- Dylan16807 10y agoOptional, but does anyone turn it off? They control their own servers, anyway.
- viraptor 10y agoOptional for the implementations. So basically your ssl library is unlikely to do it. And at that point having a "getTime()" API call in your service is simpler than having a custom patched SSL implementation.
- Dylan16807 10y agoOh, common SSL libraries don't do it? Even then you can probably rely on a Date header being attached to all your existing requests.