Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Outdated Versions of NTP Leaving Users Vulnerable - NTP v3 #138

Open
bobpf opened this issue Jul 2, 2021 · 7 comments
Open

Outdated Versions of NTP Leaving Users Vulnerable - NTP v3 #138

bobpf opened this issue Jul 2, 2021 · 7 comments

Comments

@bobpf
Copy link

bobpf commented Jul 2, 2021

It looks like your still using v3 protocol that has known vulnerabilities and is subject to be using in DDos attacks. Version 4 has been around since 2010 and earlier. Is this on your radar and if so when do you plan on upgrading the version/protocol used?

https://www.nwtime.org/outdated_versions_of_ntp_leaving_users_vulnerable/

@bobpf
Copy link
Author

bobpf commented Jul 6, 2021

Usage of NTPv3 protocol has come up on a security review. Can you comment on its usage and the possibility of getting v4 implemented as the primary protocol or as an configuration option?

@efeint01
Copy link

efeint01 commented Jul 7, 2021

Hello @bobpf . So what do you prefer to use? The library is really old and questions still remain unanswered. This is status broken

@bobpf
Copy link
Author

bobpf commented Jul 8, 2021

Switching the protocol to us NTP v4 would be preferable.

@efeint01
Copy link

efeint01 commented Jul 9, 2021

Thank you. I also using Android Secure Timer which is so good library for this, and I never see errors.

@bobpf
Copy link
Author

bobpf commented Jul 12, 2021

How does Secure Timer related to NTP v4?

@kaushikgopal
Copy link
Collaborator

@bobpf : first priority is probably landing the move to coroutines and improving the algorithm further. there's no immediate plan on moving to NTP v4 but I'm curious to read up more to get a better sense of the effort (as we gradually work on the other PRs).

do you have other helpful documentation/links that are a little more developer focused for me to read up on?

@metatron1973

This comment was marked as spam.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants