LL11 Security consideration for the threat where an attacker forces address reconfiguration
Stuart Cheshire <[email protected]>
| Newsgroups | gmane.ietf.zeroconf |
|---|---|
| Message-ID | <[email protected]> |
>> As it stands, the paragraph reads like something saying, "This >> standard says you should pick a new address if you detect a >> conflict; here are some reasons why making your implementation >> actually do that would be a terrible mistake." > >We disagree. It says something like 'doing this exposes you to >vulnerabilities.' Its like driving - you should know that you >could be smooshed every time you go on the freeway. You don't >have to go on the freeway, but it would be extremely negligent >of your driving instructor to not let you know what you are facing. >You should not neglect what precautions you have like seat belts >insurance, etc (higher layer security protocols, no assumptions >that no one would ever perform an active attack as described). I'm afraid you are still not seeing the point I am making. The point is not about the security issue. The point is about the implied response to the security issue. Having understood the security issue, is the correct response to not implement IPv4LL AT ALL? Or, is the correct response to implement IPv4LL, except the part about changing the address in response to a conflict? If the former, this is an internally-consistent and reasonable response to the problem. If the latter, this is a completely bogus and pointless response to the problem: The entire purpose of IPv4LL, the beginning and end of its reason for existence, is one thing and one thing only: An algorithm for a group of cooperating hosts, in the absence of any other authority, to arrive at a set of mutually unique IP addresses. That its only purpose. If you implement IPv4LL, except the part about ensuring that each host has a different address, then what have you implemented? Nothing. I am very serious about this. If there is anyone on this list willing to argue in favour of the "Implement IPv4LL but don't change address on conflict" position, then we need to have a serious discussion about what it is that IPv4LL is supposed to be doing. IPv4LL does *NOTHING* except maintain mutually unique IP addresses in the absence of DHCP or manual administration. What else is there for it to do? Stuart Cheshire <[email protected]> * Wizard Without Portfolio, Apple Computer, Inc. * www.stuartcheshire.org