Skip to content
This repository has been archived by the owner on Jul 16, 2020. It is now read-only.

Replay attack in account recovery #85

Open
ana0 opened this issue Apr 15, 2019 · 0 comments
Open

Replay attack in account recovery #85

ana0 opened this issue Apr 15, 2019 · 0 comments

Comments

@ana0
Copy link
Contributor

ana0 commented Apr 15, 2019

For 2.5 minutes a man-in-the-middle could overtake a users account with the same signed message they used to recover it. We should either blacklist timestamps that have been used already, or block account recoveries for more than 2.5 minutes.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant