Re: Issue 41: Mandate NAT prevention if not doing NAT-T?

Francis Dupont <[email protected]>
Newsgroups gmane.ietf.mobike
Message-ID <[email protected]>
 In your previous mail you wrote:

   > PS: mobike has no binding lifetimes (nor in fact bindings, its 
   > support is for readdressing not mobility).
   
   There's also an important difference to MIP4: there the tunnel
   is not encrypted, so redirecting the traffic allows the attacker
   to eavesdrop and modify the packets. 
   
=> the main attack is to redirect a lot of traffic to a third party
in order to overload it or its access network... BTW IPsec doesn't
imply encrypted (even to encrypt is usually no more expensive so
the option is very often taken by default).

   In MOBIKE, this is mainly a DoS thing,

=> yes, and for DoS to be encrypted is better! I am afraid the common
traffic between two SGs is larger than between MN and HA.

   and although we don't
   have binding lifetimes, we do have dead peer detection and 

=> dead peer detection can be less than enough (cf bogus keepalive
stuff in RFC 3519).

   return routability check that force the attacker to stay there
   to continue the attack forever.
   
=> yes, mobile ip and mobike have different weapons. My concern is
they share the same issue but the WGs react in very different ways.

Regards

[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.