Hacker News new | ask | show | jobs
by k_sze 491 days ago
I think that the scenario you describe requires one of two conditions:

  1. The attacker knows the time and medium through which the two persons call each other, and have control over the medium, being able to inject themselves;
  2. The attacker coerces one of the two persons to perform authentication.
You have a much bigger problem if any of the above is true.