I can certainly think of ways to make 1 time tokens work implementation wise however before we discuss this we should really take a step back and decide if we want them in the first place.
I guess n-times token where n > 1 and n < ∞ are off the table. We certainly don't want users to enter a specific n. That leaves us with three options 1) All tokens are n = ∞ 2) All tokens are n = 1 3) Give the user the choice between n = ∞ and n = 1 I think it is wise to give all tokens an expiration date. I'm still in favor of (1) and would like to work with pretty low expiration date for DoS protection. If a token leaks the user can still make it invalid by changing the secret key. In general I consider the chance of DoS pretty low because you need a new JID for every roster entry and you cant use it for targeted attacks because you have to wait for the off chance of a token to leak somehow. Or in other words: Spam/professional DoS is unlikely because spammers usually wouldn't get their hands on my tokens. 'Pranks' - when Georgs gives me a token and I decide to spam him with roster entries- are a lot of work because I need a lot of JIDs and I usually don't have those handy when I'm at a party and only have 30 mins or what ever the expiration date is. However the security section should mention that this should honor the block list of the user. cheers Daniel
_______________________________________________ Standards mailing list Info: https://mail.jabber.org/mailman/listinfo/standards Unsubscribe: [email protected] _______________________________________________
