AD comments on draft-ietf-rserpool-threats-08
Magnus Westerlund <[email protected]> Tue, 16 Oct 2007 18:38:01 +0200
| Newsgroups | gmane.ietf.rserpool |
|---|---|
| Message-ID | <[email protected]> |
Hi, A couple of comments on the threats text. 1. I am missing clear text on what the benefit would be for different attacks. Lets take a look at 2.1 to 2.5 which all deals with adding or removing PE to the ENRP database. The text is not fortcomming what benefit the attacker would have in succeeding with it. For example 2.3 is clearly desirable from two persepctives: a. DDoS, by adding a PE that is a target for DDoS attack for some popular high volume service the attacker can register a PE that a lot of PUs will try to connect to. b. Man in the middle or masqurade attack on the service provided by the real PEs. If a malicious user adds itself as a PE and handles the request he can learn a lot of service data. This was just an example, for most threats the effect should be expanded to show what this can be used for and why it is a really bad idea to do this without security. 2. This a bit more nit: Can you please provide some proper indentation of the text. It is very hard to read and it is hard to find the section headings and where each new property:value paragraph starts. Cheers Magnus Westerlund IETF Transport Area Director & TSVWG Chair ---------------------------------------------------------------------- Multimedia Technologies, Ericsson Research EAB/TVM/M ---------------------------------------------------------------------- Ericsson AB | Phone +46 8 4048287 Torshamsgatan 23 | Fax +46 8 7575550 S-164 80 Stockholm, Sweden | mailto: [email protected] ----------------------------------------------------------------------