Re: LL11 Security consideration for the threat where an attacker forces address reconfiguration
Robert Elz <[email protected]>
| Newsgroups | gmane.ietf.zeroconf |
|---|---|
| Message-ID | <[email protected]> |
Date: Sun, 31 Aug 2003 14:44:38 -0700
From: Stuart Cheshire <[email protected]>
Message-ID: <[email protected]>
Why are we still discussing this dead issue?
| Why would you, Robert Elz, *want* to use IPv4LL?
The same reason as anyone.
If I'm on a link where there are no assigned addresses, that's where
IPv4LL is supposed to apply, isn't it? Certainly, I could invent myself
an address from any arbitrary address block, and configure it, and then
talk to others (who may be using LL, or might not be), but why should
anyone be forced to do that? Even if they do know how?
Further, why should novices, using systems built by people who have
a fair idea how they're to be used (ie: there's a difference between a
system that's a portable web browser, which cares nothing about its
own IP address, and a genuine remote terminal, or even a portable server,
which usually does) have the stability of their connections made more
vulnerable than they need to be?
I see no need for one rule that must be applied by everyone - nothing
depends upon it, it is a quality of implementation issue (where neither
choice is better for all users). But even with that, I don't object to
the draft as it now stands, which is pretty close to mandating your position,
just with the security considerations making it clear what the issues are
for an implementor who blindly follows the spec without thought.
kre