[saag] Re: On path Active Attackers, and Meddlers in the M iddle

Bret Jordan <[email protected]>
Newsgroups gmane.ietf.saag
Message-ID <CA+6xXS-dbWyRBqKvi8rXOribAfJFZvA66-t8DvK43bYyrOo43Q@mail.gmail.com>
So there is active defense in both directions.

1. Forward proxy with malware protection
2. Reverse proxy for load balancing AND application firewalls / malware
protection

So on-path protections can exist on both sides. Some are there to protect
the users and their systems/data/networks and some are their to protect the
content delivery content/systems/networks. There are also legitimate needs
based on data loss prevention and child protections.

What we need to figure out is the coffee shop / pineapple device / imposter
AP problem. That is what we should really care about.

Bret


On Wed, Feb 19, 2025 at 9:08 AM Michael Richardson <[email protected]>
wrote:

>
> I've heard many bits of response about this draft, most seem supportive,
> with
> one or two believing this is just some kind of virtue signaling.
>
> My opinion is what Jon Callas said:
>
> > I also agree that we should stop -- I've never liked the term because it
> is
> > too vague, and indeed, people use it for both passive and active attacks.
>
> Jon didn't like "active on-path attacker" is unpalatable to many, we could
> do
> something else.  I'd like saag to adopt the document now (or not) because
> it
> addresses a problem that we have.
> Jon also suggested, "active in-path attacker"
>
> jon> For example, there are ad-blockers and malware blockers that are
> active,
> jon> on-path *defenses*, and even if they might have peculiar placements in
> jon> the path. And of course, the proxy firewalls of yore are also a thing.
>
> Seems reasonable to also speak about active on-path defenses.
>
> --
> Michael Richardson <[email protected]>   . o O ( IPv6 IøT consulting )
>            Sandelman Software Works Inc, Ottawa and Worldwide
>
>
>
>
> _______________________________________________
> saag mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>

_______________________________________________
saag mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.