cfrg / draft-irtf-cfrg-opaque

The OPAQUE Asymmetric PAKE Protocol
https://cfrg.github.io/draft-irtf-cfrg-opaque/draft-irtf-cfrg-opaque.html
Other
100 stars 20 forks source link

Adding note on handling online guessing attacks #456

Closed kevinlewi closed 5 months ago

kevinlewi commented 6 months ago

Adding some text to the Implementation Considerations section, by creating a subsection called "Handling Online Guessing Attacks", and highlighting the fact that servers should treat incomplete AKE interactions (after client receives KE2) as authentication failures by default.