Re: New issue 18: Threat discussion
Francis Dupont <[email protected]>
| Newsgroups | gmane.ietf.mobike |
|---|---|
| Message-ID | <[email protected]> |
In your previous mail you wrote: > 3) Unauthenticated attacker causes the IKE_SA to be > closed by modifying just one or two IKE packets (if > attacker can modify all packets, he can of course DoS). > > => I have a concern with this because it is not a MOBIKE threat > but an IKE one. I propose to rewrite it, adding for example > that MOBIKE should not add a new vulnerability (i.e., MOBIKE > should be as resillient as IKE, BTW this should be easy to do). Ok. Do you have suggested text? => I have a simpler (simplest :-) proposal: this attack doesn't work because an unauthenticated attacker cannot produce valid IKE messages after the IKE_SA_INIT exchange, i.e., only a brute force DoS can cause the IKE_SA to be closed. Thanks [email protected] PS: the key word is "unauthenticated".