LL11 Security consideration for the threat where an attacker forces address reconfiguration

Stuart Cheshire <[email protected]>
Newsgroups gmane.ietf.zeroconf
Message-ID <[email protected]>
>> As it stands, the paragraph reads like something saying, "This
>> standard says you should pick a new address if you detect a
>> conflict; here are some reasons why making your implementation
>> actually do that would be a terrible mistake."
>
>We disagree.  It says something like 'doing this exposes you to
>vulnerabilities.'  Its like driving - you should know that you
>could be smooshed every time you go on the freeway.  You don't
>have to go on the freeway, but it would be extremely negligent
>of your driving instructor to not let you know what you are facing.
>You should not neglect what precautions you have like seat belts
>insurance, etc (higher layer security protocols, no assumptions
>that no one would ever perform an active attack as described).

I'm afraid you are still not seeing the point I am making.

The point is not about the security issue. The point is about the implied 
response to the security issue.

Having understood the security issue, is the correct response to not 
implement IPv4LL AT ALL? Or, is the correct response to implement IPv4LL, 
except the part about changing the address in response to a conflict?

If the former, this is an internally-consistent and reasonable response 
to the problem.

If the latter, this is a completely bogus and pointless response to the 
problem: The entire purpose of IPv4LL, the beginning and end of its 
reason for existence, is one thing and one thing only: An algorithm for a 
group of cooperating hosts, in the absence of any other authority, to 
arrive at a set of mutually unique IP addresses. That its only purpose. 
If you implement IPv4LL, except the part about ensuring that each host 
has a different address, then what have you implemented? Nothing.

I am very serious about this. If there is anyone on this list willing to 
argue in favour of the "Implement IPv4LL but don't change address on 
conflict" position, then we need to have a serious discussion about what 
it is that IPv4LL is supposed to be doing. IPv4LL does *NOTHING* except 
maintain mutually unique IP addresses in the absence of DHCP or manual 
administration. What else is there for it to do?

Stuart Cheshire <[email protected]>
 * Wizard Without Portfolio, Apple Computer, Inc.
 * www.stuartcheshire.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.