Skip to content

Commit

Permalink
Mention unbounded state commitment
Browse files Browse the repository at this point in the history
Fixes #369
  • Loading branch information
mnot committed Jul 31, 2017
1 parent cab1cc5 commit 8b3b56b
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions draft-ietf-httpbis-origin-frame.md
Expand Up @@ -212,6 +212,9 @@ order to coalesce connections to the target onto their existing connection. Clie
this attack in a variety of ways; examples include checking for a Signed Certificate Timestamp
{{?RFC6929}}, or performing certificate revocation checks.

The Origin Set's size is unbounded by this specification, and thus could be used by attackers to
exhaust client resources. To mitigate this risk, clients can monitor their state commitment and
close the connection if it is too high.
--- back


Expand Down

0 comments on commit 8b3b56b

Please sign in to comment.