[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: threats ID



Iljitsch;

However, IP layer does not have any state of a connection,

That's not true. The routing table is state,

It is not state of a connection.


as is per-destination path MTU information.

It is a wrong understanding of PMTUD issues.


PMTUD is an issue of connections.

A few years ago, transport people finally recognized it and
had a BoF or WG to do PMTUD at the transport layer. I haven't
traced the activity, because I think PMTUD is a bad idea even
if it is implemented at the transport layer.

I'm not even going to mention IPsec.

SPI is, effectively, is a transport layer identifier just as port numbers, which is one of a reason why design of IPsec is poor.

because it is connectionless.

For a connection you need per-connection matching state in at least two places, the source and the destination. For IP you still need state, but it's per IP address or even per prefix, and it doesn't have to match on both ends. But it's still state.

See the first line of this mail.


All the shim layers are working at least at layer 4 that there
is no point to say layer 3.5

I believe NOID and certainly ODT allow layer 4 to work without changes,

You can believe so, just as you can believe NAT allow layer 4 to work without changes.

BTW, my point about man in the middle was that an attacker can still do damage without having full man in the middle capabilities, for instance by intercepting packets and injecting falsified ones, without necessarily being able to stop the flow of traffic between the endpoints.

Sure. For example, on the Internet today without M6, you can modify DNS result by sending false answer before the real one is returned.

This is important, because true man in the middle capability isn't something that is easily achieved, while "man on the sideline", where the attacker can observe data and inject his own, but not stop the real data from flowing, is fairly trivial to achieve in many situations.

Maybe. But, it has nothing to do with M6.


Masataka Ohta