If I record client sending some command via encrypted channel I can then replay it and execute this command again in the session. Fix: add serial number to commands and IO.