Re: New issue 18: Threat discussion

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   >       3) Unauthenticated attacker causes the IKE_SA to be
   >          closed by modifying just one or two IKE packets (if
   >          attacker can modify all packets, he can of course DoS).
   >    
   > => I have a concern with this because it is not a MOBIKE threat
   > but an IKE one. I propose to rewrite it, adding for example
   > that MOBIKE should not add a new vulnerability (i.e., MOBIKE
   > should be as resillient as IKE, BTW this should be easy to do).
   
   Ok. Do you have suggested text?
   
=> I have a simpler (simplest :-) proposal: this attack doesn't work
because an unauthenticated attacker cannot produce valid IKE messages
after the IKE_SA_INIT exchange, i.e., only a brute force DoS can cause
the IKE_SA to be closed.

Thanks

[email protected]

PS: the key word is "unauthenticated".
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.