Re: LL11 Security consideration for the threat where an attacker forces address reconfiguration

Stuart Cheshire <[email protected]>
Newsgroups gmane.ietf.zeroconf
Message-ID <[email protected]>
>The correct response is to make an advised decision whether to implement
>it or not.

Erik, I asked an *extremely* simple question, and you have still skirted 
around answering it.

When you write "it" in your sentence what are you talking about?

Are you saying, "The correct response is to make an advised decision 
whether to implement IPv4LL or not."

Are you saying, "The correct response is to make an advised decision 
whether to pick a new address in response to a conflict."

Which is it? This ambiguity is precisely the point I am making. Until I 
know what you are saying, I can't tell if I agree with you or not.

>If one implements the protocol, with the risks in mind,
>one can take the necessary precautions - for instance using
>application layer security, or whatever.

How does application layer security protect against Erik Nordmark's 
"distinct threat".

>You are suggesting toning down security considerations which have 
>achieved consensus in the WG.

No, I'm saying that the document should be providing answers, not 
unanswered questions. Having explained the "distinct threat", the 
document should give developers guidance about what they should do about 
that threat, not raise the issue and then leave the question unanswered.

Stuart Cheshire <[email protected]>
 * Wizard Without Portfolio, Apple Computer, Inc.
 * www.stuartcheshire.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.