3 ms·
According to the report, the replay attack is only valid for 1 hour for login links, and 1 week for sign up links. I agree that there's some risk here, but the
by InitialBP 4y ago
According to the report, the replay attack is only valid for 1 hour for login links, and 1 week for sign up links. I agree that there's some risk here, but the fix is probably straightforward (adjust timing to something more realistic or just invalidate them after use).
- mcstempel 4y agoHey there, I'm the founder/CEO at Stytch. I provided some more responses in this reply on the general post, but I'd also add that login and sign up links are invalidated after their first-time use https://news.ycombinator.com/reply?id=33164969&goto=item%3Fid%3D33162854%2333164969 https://news.ycombinator.com/reply?id=33164969&goto=item%3Fi...
- mooreds 4y ago> just invalidate them after use I can't speak for Stytch, but I know at $CURJOB, we have run into issues with this where corporate phishing protection software invalidates one time use codes. I believe it does that because it retrieves links in emails before the user clicks on them. This was an issue several of our customers have raised. So it isn't as straightforward as you might think. There's more details, including the workaround we ended up using, on the GH issue: https://github.com/FusionAuth/fusionauth-issues/issues/629 https://github.com/FusionAuth/fusionauth-issues/issues/629 PS I agree they should absolutely have guidance around link lifetime as well as safe defaults. Converting the links to one-time use seems like a good start.
- sam0x17 4y ago> the fix is probably straightforward Something I totally agree with before you've passed multiple audits. At this stage it's more a question of how the hell did this slip by 2 pen tests and 2 external audits (since they will have had to renew their SOC-2 by now. The "how this slipped through" is much more concerning than "what slipped through", though the "what slipped through" here is also rather serious imo.