RE: Security draft issue (4) - IPsec

[email protected]
Newsgroups gmane.ietf.rddp
Message-ID <[email protected]>
Caitlin,

Could you explain a couple of things:

> Nothing, except that the intermediate system buffering is
> far less likely. That *improves* security, not worsens it.

How does this improve security?  What is(are) the threat(s) whose
risk is reduced by eliminating intermediate buffering?

> What has not changed is that no matter what is in the network
> packet, the exposure of application buffers to those packets
> is under control of the application -- not of the network
> packet.
> 
> How precisely the application control the exposure of its
> buffer space, relative to its security requirements, is the
> real issue. The vulnerability of network packets is not
> an RDDP specific issue.
> 
> If the application has tailored its exposure, the attacker
> can modify the headers endlessly. They will still only be
> able to deposit the payload in the buffers the Data Sink
> ULP intended them to be deposited into.

What are the implications of that "If"?  What does an application
have to do to match the buffer exposure of TCP or SCTP via the
sockets interface?  Under what circumstances is that reasonable
(e.g., what other usage patterns does RDDP intend to enable)?
What are the potential consequences of allowing more buffer
exposure?

Thanks,
--David
----------------------------------------------------
David L. Black, Senior Technologist
EMC Corporation, 176 South St., Hopkinton, MA  01748
+1 (508) 293-7953             FAX: +1 (508) 293-7786
[email protected]        Mobile: +1 (978) 394-7754
----------------------------------------------------
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.