AD comments on draft-ietf-rserpool-threats-08

Magnus Westerlund <[email protected]> Tue, 16 Oct 2007 18:38:01 +0200
Newsgroups gmane.ietf.rserpool
Message-ID <[email protected]>
Hi,

A couple of comments on the threats text.

1. I am missing clear text on what the benefit would be for different
attacks. Lets take a look at 2.1 to 2.5 which all deals with adding or
removing PE to the ENRP database. The text is not fortcomming what
benefit the attacker would have in succeeding with it. For example 2.3
is clearly desirable from two persepctives:
a. DDoS, by adding a PE that is a target for DDoS attack for some
popular high volume service the attacker can register a PE that a lot of
PUs will try to connect to.
b. Man in the middle or masqurade attack on the service provided by the
real PEs. If a malicious user adds itself as a PE and handles the
request he can learn a lot of service data.

This was just an example, for most threats the effect should be expanded
to show what this can be used for and why it is a really bad idea to do
this without security.

2. This a bit more nit: Can you please provide some proper indentation
of the text. It is very hard to read and it is hard to find the section
headings and where each new property:value paragraph starts.

Cheers

Magnus Westerlund

IETF Transport Area Director & TSVWG Chair
----------------------------------------------------------------------
Multimedia Technologies, Ericsson Research EAB/TVM/M
----------------------------------------------------------------------
Ericsson AB                | Phone +46 8 4048287
Torshamsgatan 23           | Fax   +46 8 7575550
S-164 80 Stockholm, Sweden | mailto: [email protected]
----------------------------------------------------------------------