[openscreenprotocol] Pull Request: Adds an unguessable token to mDNS.

mfoltzgoogle has just submitted a new pull request for https://github.com/webscreens/openscreenprotocol:

== Adds an unguessable token to mDNS. ==
This PR addresses Issue #131 (Mitigations for remote network attackers) by adding an unguessable token to the mDNS TXT record.

This token must be included in the first authentication message sent to/from the agent that advertises it, to prevent remote attackers from attempting authentication.

It also fixes a couple of typos in the authentication section and clarifies that SPAKE2 is mandatory for agents to implement.
 

See https://github.com/webscreens/openscreenprotocol/pull/182

Received on Thursday, 8 August 2019 21:54:36 UTC