Re: Issue 60: Addresses in IKE_SA_INIT/AUTH (was: Comments of draft-ietf-mobike-protocol-04.txt)
Jari Arkko <[email protected]> Sun, 23 Oct 2005 13:26:51 +0300
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
Tero Kivinen wrote: >I agree that the revealing of the IP addresses is not very serious >case, but there are people who consider that unacceptable (that is why >the NAT-T uses hashes, as people did consider leaking the IP-addresses >a problem). If we leak them again here, there needs to be at least >security considerations section explaining the issue, and also explain >why we require them to be sent in clear when they could also be sent >as encrypted (i.e. hidden from passive attackers). > > We probably need the security considerations text in any case, because we have ADDITIONAL_*_ADDRESS. --Jari