[Ffmpeg-devel] SVN challenge response authentication weaknesses

Michael Niedermayer michaelni
Mon May 29 17:19:36 CEST 2006


Hi

On Mon, May 29, 2006 at 05:22:57PM +0300, Uoti Urpala wrote:
> On Mon, 2006-05-29 at 10:27 +0200, Michael Niedermayer wrote:
> > yes, i fully agree, still its an interresting excercise to see where my
> > custom scheme fails, you already found one big flaw (the seq num overhead)
> > can you find another in my new system? :)
> 
> Your new system doesn't have any redundancy in the data stream and so
> cannot detect modifications. It might be hard to change a block to a

you could add a checksum to each messages (not packet) to protect against
that ...

[...]
-- 
Michael     GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB

In the past you could go to a library and read, borrow or copy any book
Today you'd get arrested for mere telling someone where the library is




More information about the ffmpeg-devel mailing list