4 ms·
However, this is susceptible to a man-in-the-middle attack, still. A malicious man-in-the-middle could simply send an old timestamp which was already validated.
by ma_mazmaz 12y ago
However, this is susceptible to a man-in-the-middle attack, still. A malicious man-in-the-middle could simply send an old timestamp which was already validated. The best alternative would be to require the time server to return a signed timestamp plus challenge to prove that it was sent by the actual server. Unfortunately, this would incur computational cost on the part of the time server, which may make such a scheme impractical.
- iancarroll 12y agoSome TSAs (GeoTrust) support TLS which solves this problem. Surprisingly (given they sell the product to do that) it doesn't seem many others do...