Re: LL11 Security consideration for the threat where an attacker forces address reconfiguration

"Philip Nye" <[email protected]>
Newsgroups gmane.ietf.zeroconf
Organization Engineering Arts
Message-ID <001801c3573d$71f159d0$131010ac@aldebaran>
> From: "Stuart Cheshire" <[email protected]>
>
> We were discussing whether the "Security Considerations" text might lead
> some implementers to conclude that it's better to cling to a conflicting
> address and fight over it, rather than give up and pick another.

The draft seems fairly clear to me - Section 2.5 says that you have a single
chance to defend your LL address but MUST reconfigure if the conflict
persists.

Section 5 points out some risks and says that security is up to the
implementer. It notes that 2.5 requires reconfiguration. It recommends that
you attempt to close existing connections as a part of reconfiguring your
address. I cannot see that section 5 provides a getout clause for an
implementer who doesn't want to reconfigure.

Is there an ambiguity that I have missed?

Philip
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.