Re: draft-state-sip-relay-attack-00

Hadriel Kaplan <[email protected]>
Newsgroups gmane.ietf.sip
Message-ID <E6C2E8958BA59A4FB960963D475F7AC314C4FAA08C@mail>

> -----Original Message-----
> From: Raphael Coeffic [mailto:[email protected]]
> Sent: Monday, March 09, 2009 7:42 AM
>
> That's a good point. Requiring the user to be registered and only
> accepting requests from the registered contacts provide a fair-enough
> level of security concerning the attack debated. But I am still hoping
> that we could find a solution not requiring this kind of measures, which
> I would call "user-restricting".

How is it "user-restricting" to require a UA to generate a REGISTER request?  Most humans don't generate the REGISTER request by hand - typically software does it for them.  :)
I mean at that point you can also just say "digest authentication is user-restricting".

-hadriel
_______________________________________________
Sip mailing list  https://www.ietf.org/mailman/listinfo/sip
This list is for NEW development of the core SIP Protocol
Use [email protected] for questions on current sip
Use [email protected] for new developments on the application of sip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.