Re: LL11 Security consideration for the threat where an attacker forces address reconfiguration

Robert Elz <[email protected]>
Newsgroups gmane.ietf.zeroconf
Message-ID <[email protected]>
    Date:        Mon, 23 Jun 2003 20:37:46 -0700
    From:        Stuart Cheshire <[email protected]>
    Message-ID:  <[email protected]>

  | If the latter, this is a completely bogus and pointless response to the 
  | problem: The entire purpose of IPv4LL, the beginning and end of its 
  | reason for existence, is one thing and one thing only: An algorithm for a 
  | group of cooperating hosts, in the absence of any other authority, to 
  | arrive at a set of mutually unique IP addresses. That its only purpose.

Yes, and that is fine.   And regardless of whether or not addresses
are changed upon late conflict detection does not make much difference
to that.

That is, the mechanism doesn't have to be perfect in every possible
scenario to be useful, does it?

  | If you implement IPv4LL, except the part about ensuring that each host 
  | has a different address, then what have you implemented? Nothing.

Of course, so you do implement that part, and make sure you get a
unique address.   Then, if it later turns out you were wrong, one
reasonable option is to just say "I give up".

That is, it works most of the time, but in some rare situations, it
might not.

Aside from deliberate attacks, which nothing in the LL draft will allow
a host to survive, the only way this problem can occur, that I'm aware
of, if when two previously independent links are connected to become
one link (bridging enabled, or whatever).

In that circumstance, if address conflicts occur, it is entirely
reasonable for a host, if it wants, to simply cling onto its address
and refuse to let go.   If the other host changes, then everything
is OK, there was no real need for both of them to alter addresses.
If both alter, that's OK too.   If both are determined to hold their
addresses, then those two are effectively locked off the LL link.

For some hosts, that may very well be the best solution - I can't
talk, but I will make sure the other guy can't either.   It all
depends just what the host is doing.

  | I am very serious about this. If there is anyone on this list willing to 
  | argue in favour of the "Implement IPv4LL but don't change address on 
  | conflict" position, then we need to have a serious discussion about what 
  | it is that IPv4LL is supposed to be doing. IPv4LL does *NOTHING* except 
  | maintain mutually unique IP addresses in the absence of DHCP or manual 
  | administration. What else is there for it to do?

You are wanting perfection where no prefection is possible.   If you claim
that IPv4LL should not exist if it fails to guarantee that every host
(implementing it) will always get a usable v4LL address that it can use,
then you might as well abandon v4LL now, as we know that is simply not
possible to achieve.

Much better is to abandon that requirement, and just allow it to work
most of the time.

Also note, that no-one is requiring that hosts hold onto their addresses.
Just that the implementor consider the issues involved with changing,
and whether that allows an unreasonable security issue for the host.

kre
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.