[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Fwd: Minutes / Notes



Pekka;

> > Binding between locators and identifiers in single packets have
> > just enough security.

It should also be noted that binding between locators and identifiers
in single DNS reply packets have just enough security.

> Strongly disagree.  See the flooding attacks in
> http://www.ietf.org/internet-drafts/draft-nikander-mobileip-v6-ro-sec-01.txt
> 
> They do not, as such, directly apply to multi-homing,

Notification of locator changes, of course, needs its own
security, which does not apply to multi-homing issue here,
not even indirectly.

> but you can fairly easily find out variants that do.

Wrong.

The variant (or a simple case) is an issue to be addressed by
return routability and/or DNS reverse/forward mapping just as
current IPv4 or 6.

							Masataka Ohta