Re: AoE -- was Re: todolist

"Ian Latter" <[email protected]>
Newsgroups gmane.linux.cluster.openmosix.devel
Message-ID <[email protected]>
We're going to have to agree to disagree;

  - I stand by my (original) claim that AoE's not delivering any
    security objective - and that advisory comments should
    reflect this. Take the sample from my previous email 
    (from http://www.coraid.com/pdfs/articles/LinuxDevices.pdf) 
    and revise it, with your comments - it could read;
      "AoE is not a routable protocol (this provides inherent 
       security *)
       [...]
       * on a TRUSTED network"


However, to your other points, I also believe;

  - Trusted isn't automatically achieved from being one 
     hop away from untrusted.

  - An IDE ribbon cable has physical controls - these would
    need to be replicated by your SAN LAN for it to be truly 
    equivalent (and that would preclude multi-host access)

  - That Ethernet can be forwarded/proxied and "routed", 
     which means AoE can too.


We also differ when you consider that;

  - openMosix is not suppost to be used outside of 
    "trusted" networks either, but that doesn't stop 
    fools (damn fools) from hooking it up to their publicly 
    addressed university campuses. (Though at least it 
    wasn't promoted/touted as "secure" by the oM 
    developers .. see "Implementation Vulnerability 
    (Node Vulnerability)", p10;
       http://midnightcode.org/papers/White%20Paper%20-%20Security%
20and%20openMosix.pdf





----- Original Message -----
>From: "Tracy R Reed" <[email protected]>
>To: "Ian Latter" <[email protected]>
>Subject:  Re: [Openmosix-devel] AoE -- was Re:  todolist
>Date: Sat, 09 Sep 2006 22:48:02 -0700
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Ian Latter wrote:
> 
> >   I'm fine with the protocol not supplying security, as
> > long as its not quoted that way ... just show people how 
> > to use IPSEC and L2TP to route this securely, instead of 
> > advertising it for what it isn't.
> 
> Hold on now...I'm not advertising it for what it isn't. AoE, like most
> any SAN protocol, is intended to be run on a TRUSTED network. Not being
> routable means it should not be able to escape your trusted network. At
> my shop we run AoE on its own network completely separate from the 
rest
> of our traffic just as you would with any other SAN. To do anything else
> is foolish. As such it cannot be sniffed by anyone not on that network.
> Encryption and authentication are not necessary on a trusted network.
> Consider an AoE SAN to be just like the IDE ribbon cable connecting your
> drive to your motherboard because that is essentially what it is. If
> someone can tap into your IDE ribbon cable they can see your data just
> as they can if you somehow allow them onto your AoE SAN.
> The beauty of AoE is simplicity. If you wrap it in IPSEC and L2TP you
> lose that. If you want a routable SAN protocol use iSCSI.
> 
> I stand by my claim (and Coraid's) that not being routable is a security
> advantage.
> 
> - --
> Tracy R Reed
> http://ultraviolet.org
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.5 (GNU/Linux)
> Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org
> 
> 
iD8DBQFFA6cS9PIYKZYVAq0RApLwAJoDXPMStveMw1eeSOPrgfK4qfFyegCgg
eD2
> uSMdkRC/qaA50CLVh4xULj0=
> =RwJp
> -----END PGP SIGNATURE-----
> 
> -------------------------------------------------------------------------
> Using Tomcat but need to do more? Need to support web services, 
security?
> Get stuff done quickly with pre-integrated technology to make your job 
easier
> Download IBM WebSphere Application Server v.1.0.1 based on Apache 
Geronimo
> http://sel.as-us.falkag.net/sel?
cmd=lnk&kid=120709&bid=263057&dat=121642
> _______________________________________________
> openMosix-devel mailing list
> openMosix-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
> https://lists.sourceforge.net/lists/listinfo/openmosix-devel
> 


--
Ian Latter
Late night coder ..
http://midnightcode.org/


-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.