Skip to content

Commit

Permalink
Ask servers to limit use of tokens to only once
Browse files Browse the repository at this point in the history
  • Loading branch information
huitema committed Nov 28, 2018
1 parent 1a93cb8 commit baeb987
Showing 1 changed file with 3 additions and 0 deletions.
3 changes: 3 additions & 0 deletions draft-ietf-quic-transport.md
Expand Up @@ -1637,6 +1637,9 @@ able to reuse a token. To avoid attacks that exploit this property, a server
can limit its use of tokens to only the information needed validate client
addresses.

Fraudulently obtained tokens could enable botnets to use servers as amplifiers
in DDOS attacks. Servers SHOULD protect against such attacks by ensuring that
tokens are used by clients only once.

### Address Validation Token Integrity {#token-integrity}

Expand Down

0 comments on commit baeb987

Please sign in to comment.