Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Delivered parcels can be redelivered after they've been collected #210

Open
gnarea opened this issue Sep 30, 2020 · 0 comments
Open

Delivered parcels can be redelivered after they've been collected #210

gnarea opened this issue Sep 30, 2020 · 0 comments
Labels
bug Something isn't working

Comments

@gnarea
Copy link
Member

gnarea commented Sep 30, 2020

When a parcel is redelivered before it's been collected, the new parcel would supersede its predecessor per the Relaynet specs. However, they parcel will be deleted once collected, so it's possible for an attacker to redeliver a parcel.

This could lead to replay attacks if private gateways fail to ignore previously-processed, incoming parcels.

@gnarea gnarea added the bug Something isn't working label Sep 30, 2020
@gnarea gnarea added this to the Production release milestone Sep 30, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant