[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Simple Security - Layered Filtering should be in the document
On Jul 31, 2009, at 11:18, Yaron Sheffer wrote:
Your argument is valid today. But once any tunnel-based transition
mechanism
is standardized and widely adopted by commercial operating systems,
there
will be untunneling done by default, with no security mechanisms
attached.
Note that IPsec requires access control from all implementations,
but other
mechanisms don't. So suddenly you have to be wary of "tunneled
burglars",
too.
We already have two standard, automatic, transitional tunnel
mechanisms: 6to4 and Teredo, both of which are explicitly treated in
the current draft. The DS-Lite protocol comes to mind as a third
example, but its automatic usage would have to be enabled directly by
the residential gateway with a DHCP6, which would be *stupid* because
it would make infinitely more sense to terminate the DS-Lite tunnel in
the gateway directly.
It's hard to imagine why any new transitional tunnel mechanisms might
need to be developed, widely deployed and enabled in ubiquitous
default platform configurations.
Do you know about something else that the rest of us don't? Please
share.
--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering