[jdev] Replay attacks?

Justin Karneges justin-keyword-jabber.093179 at affinix.com
Wed Feb 8 00:26:29 CST 2006


On Tuesday 07 February 2006 21:37, Adam Hunt wrote:
> level XMPP would be susceptible to replay attacks.  Has any work been done
> on securing against such attacks?

Session-based security (JEP-116) solves replay attacks.  For simpler single 
message security, I have a replay prevention scheme in jep-secure:
  http://delta.affinix.com/specs/jep-secure.html

-Justin



More information about the JDev mailing list