RE: Issue 41: Mandate NAT prevention if not doing NAT-T?

<[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
Francis Dupont wrote:

>  In your previous mail you wrote:
> 
>    I'm curious, how exactly does RFC 3519 mitigate this issue?
>    
> => short lifetimes (so the attacker has to stay and increases its
> chance to be caught). The whole thing is explained in the security
> considerations...
> 
> [email protected]
> 
> PS: mobike has no binding lifetimes (nor in fact bindings, its 
> support is for readdressing not mobility).

There's also an important difference to MIP4: there the tunnel
is not encrypted, so redirecting the traffic allows the attacker
to eavesdrop and modify the packets. 

In MOBIKE, this is mainly a DoS thing, and although we don't
have binding lifetimes, we do have dead peer detection and 
return routability check that force the attacker to stay there
to continue the attack forever.

Best regards,
Pasi
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.