[FFmpeg-devel] Fix NTP time in RTCP SR packets

Michael Niedermayer michaelni
Tue Feb 19 18:06:48 CET 2008


On Mon, Feb 18, 2008 at 01:48:22PM +0100, Luca Abeni wrote:
> Hi all,
>
> Luca Abeni wrote:
>> Hi Michael,
>> Michael Niedermayer wrote:
>> [...]
>>>> Uh, as I understand it, this sends out the local time with usec
>>>> precision. The server sure as hell does not know that, and it could e.g.
>>>> be used to guess values if someone uses a stupid random number
>>>> generator, system/network load and other things.
>>>> IOW this is one of the things everyone planning a side-channel attack
>>>> just dreams of.
>>> Use time/1000*1000 and you loose less information.
>> If this is ok from the security point of view, I think this is the best
>> solution... I'll send a patch later
>
> And here is the patch...

You are maintainer of rtpenc.c commit whatever you think is best. That said
yes iam fine with the patch.

[...]
-- 
Michael     GnuPG fingerprint: 9FF2128B147EF6730BADF133611EC787040B0FAB

I count him braver who overcomes his desires than him who conquers his
enemies for the hardest victory is over self. -- Aristotle
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature
URL: <http://lists.mplayerhq.hu/pipermail/ffmpeg-devel/attachments/20080219/a77e6742/attachment.pgp>



More information about the ffmpeg-devel mailing list