Re: [v6ops] [IPv6] Why folks are blocking IPv6 extension headers? (Episode 1000 and counting) (Linux DoS)
Fernando Gont <[email protected]>
| Newsgroups | gmane.ietf.opsec,gmane.ietf.v6ops,gmane.ietf.ipv6 |
|---|---|
| Organization | SI6 Networks |
| Message-ID | <[email protected]> |
Hi, Brian, On 23/5/23 00:41, Brian E Carpenter wrote: [...] > > That depends where you choose to apply the zero trust model. As Steve > Bellovin argued many years ago in his distributed firewalls paper, > distributing the trust model to the end systems is best, because you no > longer have to trust any intermediate systems. Given the amount of things that get connected to the Net (smart bulbs, refrigerators, etc.) -- and that will super-likely never receive security updates, you may have to rely on your own network. For instance, I wouldn't have my smart TV "defend itself". Cheers, -- Fernando Gont SI6 Networks e-mail: [email protected] PGP Fingerprint: F242 FF0E A804 AF81 EB10 2F07 7CA1 321D 663B B494