Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Protect against Resync replay attacks #73

Merged
merged 2 commits into from
Mar 30, 2020
Merged

Conversation

loongy
Copy link
Contributor

@loongy loongy commented Mar 30, 2020

This PR fixes #50 by introducing timestamps to Resync messages, and ignoring Resync messages that have timestamps outside of a reasonable range. More advanced protections have been deferred to #72.

@loongy loongy added the bug Something isn't working label Mar 30, 2020
@loongy loongy added this to the v1.3.0 milestone Mar 30, 2020
@loongy loongy changed the base branch from master to release/1.3.0 March 30, 2020 03:59
@loongy loongy merged commit 03df5a3 into release/1.3.0 Mar 30, 2020
@loongy loongy deleted the fix/resync-replay branch March 30, 2020 04:42
@loongy loongy restored the fix/resync-replay branch March 30, 2020 22:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Protect against Resync replay attacks
1 participant