Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

ntp authentication is broken: http://zero-entropy.de/autokey_analysis.pdf and it was the same guy who found the new vulnerabilities :-)


In order for the attack to succeed Eve needs to be able to MITM every configured ntp server association and do so before the daemon starts up.

FYI Stephen Röttger is also the same guy who is a co-author of the two IETF proposals for the successor to autokey; Network Time Security[1] and Crypto Message Syntax for NTS[2].

[1]: https://tools.ietf.org/html/draft-ietf-ntp-network-time-secu...

[2]: https://tools.ietf.org/html/draft-ietf-ntp-cms-for-nts-messa...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: