Re: (a proposal of light-weight iTrace authentication) Re: Potential agenda for SF meeting

"Marcus Leech" <[email protected]> Fri, 07 Feb 2003 15:20:43 -0500
Newsgroups gmane.ietf.itrace
Organization Nortel Networks
Message-ID <[email protected]>
"S. Felix Wu" wrote:
>
> 
>         (1). It can produce a challenge (a nouce) and send the
>              received iTrace message back to the producer of this
>              iTrace message. If the producer then sends back a
>              "Yes" message (with the correct nouce) to validate
>              the message, then we will "trust in the weak sense"
>              this iTrace message.
>
I would say that this is "trust in the very weak sense".  The question to ask
  is whether this is too weak to be of any use.  The bad guy can potentially
  compromise part of the path between a DDoS source and its nearest router, which
  would mean that "YES" messages from this couldn't be trusted.



-- 
----------------------------------------------------------------------
Marcus Leech                             Mail:   Dept 8M70, MS 012, FITZ
Advisor                                  Phone: (ESN) 393-9145  +1 613 763 9145
Security Architecture and Planning       Fax:   (ESN) 393-9435  +1 613 763 9435
Nortel Networks                          [email protected]
-----------------Expressed opinions are my own, not my employer's------