Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add random delay on OPN failure against timing attacks #1651

Open
2 tasks done
mlgiraud opened this issue Mar 12, 2018 · 0 comments
Open
2 tasks done

Add random delay on OPN failure against timing attacks #1651

mlgiraud opened this issue Mar 12, 2018 · 0 comments

Comments

@mlgiraud
Copy link
Contributor

mlgiraud commented Mar 12, 2018

Description

Part 2 v1.03 §6.3 mentions including a random delay when closing a socket due to an error whilst establishing a SecureChannel to reduce the possibility of an attack that uses timings to determine what failed during the establishing phase.
I don't think we implemented this yet.

Checklist

Please provide the following information:

  • open62541 Version (release number or git tag): master
  • Critical issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant