Skip to content

involontary replay attack when unshielding #144

Description

@brenzi

unshielding suffers from replay attacks, even without bad intentions:

If more than one worker is registered for a shard, these workers all send the unshield_funds(account, amount, shard) extrinsic. The pallet has no way to know that these are results of the same TrustedCallSigned::unshield() (which suffers another replay attack until we solve #89)

Of course, an adversary could also expoit this replay attack.

Mitigation: keep track of all confirmed TrustedCallSigned.

The substratee_registry::confirm_call(<TrustedCallSigned>) keeps a registry of confirmed calls. This registry could be a storage_map(Hash) -> u32 and counts the number of confirmations N per call.

If N > 0, we don't unshield because it has already been done

We might merge the confirm_call and unshield_funds extrinsic into one for that purpose. No need to spend two transactions for a single purpose

Please update the book too

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

F1-securitypossible vulnerabilityF2-bugSomething isn't working

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions