Re: (a proposal of light-weight iTrace authentication) Re: Potential agenda for SF meeting
"Marcus Leech" <[email protected]> Fri, 07 Feb 2003 15:20:43 -0500
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Organization | Nortel Networks |
| Message-ID | <[email protected]> |
"S. Felix Wu" wrote: > > > (1). It can produce a challenge (a nouce) and send the > received iTrace message back to the producer of this > iTrace message. If the producer then sends back a > "Yes" message (with the correct nouce) to validate > the message, then we will "trust in the weak sense" > this iTrace message. > I would say that this is "trust in the very weak sense". The question to ask is whether this is too weak to be of any use. The bad guy can potentially compromise part of the path between a DDoS source and its nearest router, which would mean that "YES" messages from this couldn't be trusted. -- ---------------------------------------------------------------------- Marcus Leech Mail: Dept 8M70, MS 012, FITZ Advisor Phone: (ESN) 393-9145 +1 613 763 9145 Security Architecture and Planning Fax: (ESN) 393-9435 +1 613 763 9435 Nortel Networks [email protected] -----------------Expressed opinions are my own, not my employer's------