seanmonstar / gryphon

HTTP Request Signing with Ed25519
Mozilla Public License 2.0
4 stars 2 forks source link

replay attacks #2

Closed timkuijsten closed 9 years ago

timkuijsten commented 9 years ago

Am I right to conclude that replay attacks are not prevented but only mitigated to a window of 60 seconds?

seanmonstar commented 9 years ago

You can pass a timeSkew option to change from the 60 seconds.

timkuijsten commented 9 years ago

Ic, still mitigated, not prevented, but proper prevention would cause a round trip with the server first I guess.