Project

General

Profile

Feature #10499

Verify the IP address of the sender in the channel change message

Added by Elliott McCrory almost 5 years ago. Updated about 2 years ago.

Status:
Remission
Priority:
Low
Category:
Java Code
Start date:
10/13/2015
Due date:
% Done:

0%

Estimated time:
Duration:

Description

On line 196 of DCProtocol, there is a "TODO" comment that suggests that we verify that the IP address in the change-channel message matches the IP address of the actual Internet sender.

The message asks for this check, but we do not do it. Moreover, it is not clear that (a) this adds any security and (b) that this is a useful thing.

History

#1 Updated by Elliott McCrory about 2 years ago

  • Status changed from New to Remission

This is theoretically possible, but, in practical terms, very hard to do. So, declaring it "in remission"



Also available in: Atom PDF