3 ms·
A nonce is not a key, it's a piece of random that is meant to be used at most once. If an attacker sees valid nonces on a VM, and knows of another VM sharing t
by Rygian 1y ago
A nonce is not a key, it's a piece of random that is meant to be used at most once.
If an attacker sees valid nonces on a VM, and knows of another VM sharing the same nonces, then your crypto on both* VMs becomes vulnerable to replay attacks.
*read: all
- nodesocket 1y agoHow would a reply attack work in production assuming multiple VMs share a nonce?
- saagarjha 1y agoYou record the traffic going to one VM and send it to another, which will now accept it because the nonce is the same.
- trollied 1y ago“Number ONCE”. NONCE. Indeed.