[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Simple Security - Layered Filtering should be in the document



On Jul 31, 2009, at 11:18, Yaron Sheffer wrote:

Your argument is valid today. But once any tunnel-based transition mechanism is standardized and widely adopted by commercial operating systems, there will be untunneling done by default, with no security mechanisms attached. Note that IPsec requires access control from all implementations, but other mechanisms don't. So suddenly you have to be wary of "tunneled burglars",
too.

We already have two standard, automatic, transitional tunnel mechanisms: 6to4 and Teredo, both of which are explicitly treated in the current draft. The DS-Lite protocol comes to mind as a third example, but its automatic usage would have to be enabled directly by the residential gateway with a DHCP6, which would be *stupid* because it would make infinitely more sense to terminate the DS-Lite tunnel in the gateway directly.

It's hard to imagine why any new transitional tunnel mechanisms might need to be developed, widely deployed and enabled in ubiquitous default platform configurations.

Do you know about something else that the rest of us don't? Please share.


--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering