3 ms·
To answer the questions in this thread: having a preshared key (PSK) doesn't save you. The problem remains replay attacks: even if you have a PSK, if you don't
by doomrobo 4y ago
To answer the questions in this thread: having a preshared key (PSK) doesn't save you. The problem remains replay attacks: even if you have a PSK, if you don't have a fresh session, then an adversary can replay old messages back to you.
The only solution to the replay problem is to have the poor-entropy machine keep a strikelist of all the messages (or hashes thereof) it has ever received from the entropy service. Thus, when receiving a new message, it can make sure it's not a replay. Of course, this means that you've turned a stateless protocol into a stateful one, and require non-volatile storage on the device for a potentially long period of time.
As far as I know, nobody actually does this.