Re: [v6ops] [IPv6] Why folks are blocking IPv6 extension headers? (Episode 1000 and counting) (Li nux DoS)
hsyu <[email protected]>
| Newsgroups | gmane.ietf.opsec,gmane.ietf.v6ops,gmane.ietf.ipv6 |
|---|---|
| Message-ID | <[email protected]> |
Hi, Tom Hi, David, On 22/5/23 18:05, David Farmer wrote: [...] I think that many of us are still reeling from default configuration of certain "firewalls" that banks seemed like, which dropped packets containing ECN, and TCP options, and made it very very difficult to deploy new things. Even when at the IETF standards level... (so "innovation with permission") So, I think we need "permissionless innovation" at the Internet level. Nevertheless, that doesn't mean "innovation with permission" isn't appropriate in some or even many situations. For example, in a situation involving public safety, like a nuclear reactor or a missile control system. We can all agree that "permissionless innovation" isn't necessarily appropriate in situations like these. For the Security guy, the "nuclear reactor" is the infrastructure that, if compromised or DoS, causes clients to complain, money to be lost, and eventually, staff to be fired. Fernando, That's the viewpoint for a Network Security guy, but as a Host Security guy, network policy ostensibly put in place to protect the host is irrelevant. The reason should be obvious, unless there was a network security policy consistently implemented across all networks, we, host developers and application developers, can't count on it and it really doesn't help securing the host. In fact it's more likely that these inconsistent policies are counter productive since we have to insert hacks to try to work around network secure policies which themselves could create issues (for instance, think about the hacks we need to do to try to keep an anonymous stateful firewall in the path from arbitrarily evicting our connection from its cache). Tom Tom, I agree with you. Host operators and network operators have different priorities when it comes to security and efficiency. Host operators focus more on ensuring basic data security while improving the speed of data transmission. On the other hand, network operators prioritize network security while striving to maximize network efficiency. Based on what I've observed, most data breaches on the internet occur due to security vulnerabilities in applications (like leaks of usernames and passwords) or physical intrusions, rather than issues during data transmission over the network. During the process of transmitting data through the network, there is indeed a Nash equilibrium relationship between security and efficiency, and this balance determines the overall user experience. If we excessively prioritize security without considering efficiency, it can lead to slower performance and reduce the usefulness for users. Similarly, if we focus too much on network efficiency without ensuring adequate security measures, it can result in data breaches, which also diminishes the user experience. Therefore, to achieve the best user experience, both security and efficiency need to be taken into account and maintained. The network also experiences what is called the "bucket effect," where the security of the entire network depends on the weakest part within it. Even if most subnetworks within the network are secure, the presence of a vulnerability in one subnetwork can pose a threat to the overall network security. Therefore, network operators need to pay special attention to and strengthen the security of the weakest subnetwork to ensure the overall security of the entire network. Johnson Yu Yes, I love to play with EHs.... in a lab. :-) Thanks, -- Fernando Gont e-mail: [email protected] PGP Fingerprint: 7F7F 686D 8AC9 3319 EEAD C1C8 D1D5 4B94 E301 6F01 _______________________________________________ v6ops mailing list [email protected] https://www.ietf.org/mailman/listinfo/v6ops _______________________________________________ v6ops mailing list [email protected] https://www.ietf.org/mailman/listinfo/v6ops 喻海生Haisheng Yu (Johnson)下一代互联网关键技术和评测北京市工程研究中心有限公司[email protected]