4 ms·
The article refers to a "cookie" as a "biscuit" "Lacking a reliable way to detect retransmission, we remove the replay protection mechanism and store the respo
by gzer0 4y ago
The article refers to a "cookie" as a "biscuit"
"Lacking a reliable way to detect retransmission, we remove the replay protection mechanism and store the responder state in an encrypted cookie called “the biscuit” instead. Since the responder does not store any session-dependent state until the initiator is interactively authenticated, there is no state to disrupt in an attack."
Both WG and PQWG are vulnerable to state disruption attacks; they rely on a timestamp to protect against replay of the first protocol message. An attacker who can tamper with the local time of the protocol initiator can inhibit future handshakes, rendering the initiator’s static keypair practically useless.
The use of the insecure NTP protocol is the reason for the "cookie" / "Biscuit" mechanism.
- Fnoord 4y agoAFAIK a NTP client doesn't accept a value which highly differentiates from the current time. At least, not without user interaction. Does that render this attack less likely?
- sevenoftwelve 4y agoRosenpass author here. It does yes. But it is a mitigation, not a real fix. An attacker could still just speed up time. Although not being able to produce a KillPacket for the year three thousand is a good thing :)