RE: draft-purser-pppext-pppcn-00.txt

James Carlson <[email protected]>
Newsgroups gmane.ietf.pppext
Message-ID <[email protected]>
Kevin Purser (QA/EMC) writes:
> > No additional security risks? Really? How about revealing an 
> > IP address
> > before you have even authenticated the peer? Or accepting an unlimited
> > number of IP packets waiting for some negotiation to complete?
> > Neither of these significant security issues are present in RFC1661,
> > and both represent leaks that can easily be abused. If anything, this
> > draft _adds_ serious security risks.
> 
> Perhaps the text wasn't clear enough.  While the IP address may be "revealed" to the peer, it's of no consequence if packets sent by that peer will *not* be forwarded by the authenticating peer until *after* completing the auth phase, right?  And the sending of IP packets was really only a further optimization to the proposal, not a requirement.

I agree with that.  The proposal doesn't omit the required security
steps, and IP addresses seem to me to be hardly something that could
be considered "secrets."

-- 
James Carlson, IP Systems Group                <[email protected]>
Sun Microsystems / 1 Network Drive         71.234W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.497N   Fax +1 781 442 1677
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.