<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.mozilla.org/index.php?action=history&amp;feed=atom&amp;title=Identity%2FSecurity%2FReplay_attacks</id>
	<title>Identity/Security/Replay attacks - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.mozilla.org/index.php?action=history&amp;feed=atom&amp;title=Identity%2FSecurity%2FReplay_attacks"/>
	<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Identity/Security/Replay_attacks&amp;action=history"/>
	<updated>2026-09-21T06:46:56Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.10</generator>
	<entry>
		<id>https://wiki.mozilla.org/index.php?title=Identity/Security/Replay_attacks&amp;diff=651367&amp;oldid=prev</id>
		<title>Fmarier: Created page with &quot;= Assertion replay =  == Risks ==  * If an assertion is captured by an attacker, it can be replayed to an RP to gain entry to that site and impersonate a user there.  == Mitig...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.mozilla.org/index.php?title=Identity/Security/Replay_attacks&amp;diff=651367&amp;oldid=prev"/>
		<updated>2013-05-02T05:56:58Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;= Assertion replay =  == Risks ==  * If an assertion is captured by an attacker, it can be replayed to an RP to gain entry to that site and impersonate a user there.  == Mitig...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= Assertion replay =&lt;br /&gt;
&lt;br /&gt;
== Risks ==&lt;br /&gt;
&lt;br /&gt;
* If an assertion is captured by an attacker, it can be replayed to an RP to gain entry to that site and impersonate a user there.&lt;br /&gt;
&lt;br /&gt;
== Mitigations ==&lt;br /&gt;
&lt;br /&gt;
* assertions are only valid for 2 minutes&lt;br /&gt;
* we recommend that sites send the assertion to their backend over HTTPS&lt;br /&gt;
* verifiers could keep track of assertions they have seen in the last 2-3 minutes (&amp;lt;tt&amp;gt;verifier.login.persona.org&amp;lt;/tt&amp;gt; doesn&amp;#039;t do that)&lt;br /&gt;
&lt;br /&gt;
== Notes ==&lt;br /&gt;
&lt;br /&gt;
Typically, on HTTP-only sites, attackers can already steal session cookies. The ability to create a new session after stealing an assertion is more useful since it allows the attacker to keep going after the real user logs out of the site with his/her session.&lt;/div&gt;</summary>
		<author><name>Fmarier</name></author>
	</entry>
</feed>