Skip to content

[Question] Stateless Reset Oracle Attack #555

Open
@reteps

Description

@reteps

Hi there, I am performing a research project to follow up some of the analysis done in "A Quic(k) Security Overview: A Literature Research on Implemented Security Recommendations"

Image

According to their findings, the Stateless Reset Oracle defenses described in RFC 9000 21.11 has not been implemented in aiohttp.

I was hoping to:

  1. confirm that this isn't something the library handles
  2. check whether you would accept a PR defending against this attack

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions