I can certainly think of ways to make 1 time tokens work implementation
wise however before we discuss this we should really take a step back and
decide if we want them in the first place.

I guess n-times token where n > 1 and n < ∞ are off the table. We certainly
don't want users to enter a specific n.

That leaves us with three options
1) All tokens are n = ∞
2) All tokens are n = 1
3) Give the user the choice between n = ∞ and n = 1

I think it is wise to give all tokens an expiration date.

I'm still in favor of (1) and would like to work with pretty low expiration
date for DoS protection. If a token leaks the user can still make it
invalid by changing the secret key.
In general I consider the chance of DoS pretty low because you need a new
JID for every roster entry and you cant use it for targeted attacks because
you have to wait for the off chance of a token to leak somehow.
Or in other words: Spam/professional DoS is unlikely because spammers
usually wouldn't get their hands on my tokens. 'Pranks' - when Georgs gives
me a token and I decide to spam him with roster entries- are a lot of work
because I need a lot of JIDs and I usually don't have those handy when I'm
at a party and only have 30 mins or what ever the expiration date is.

However the security section should mention that this should honor the
block list of the user.

cheers
Daniel
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to