-
Notifications
You must be signed in to change notification settings - Fork 4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
- #3008
Comments
vmess依靠时间戳进行验证 这是系统内置的 与时区或政府是否实行夏令时没有任何关系 只要确保系统时间准确即可 |
VMess 依赖时间戳是为了防重放攻击,你提出的设计类似于 REALITY 的 session id 部分,不检查时间戳时它自身不防重放攻击 且它只是比固定密码(客户端密码泄露可以全解密)好一点点,仍缺乏严格意义上的前向安全性(服务端私钥泄露可以全解密),且以原始形式发送 curve25519 public key 可被识别 net4people/bbs#287 (comment) , 去年在讨论抗量子的密钥交换时我想过用它来设计 VLESS 的加密, 如果你实在是不想依赖时间戳,可以看一下 shadowsocks/shadowsocks-org#177 , 依赖时间戳、不依赖密钥交换的可以看一下 shadowsocks/shadowsocks-org#178 |
需要用时间戳防止重放主要是为了无状态0rtt 如果还加一轮协商又要多一个rtt了 |
answered |
No description provided.
The text was updated successfully, but these errors were encountered: