Minor error: the text currently says For example, there are security risks relating to IP source routing that are precluded by AH, but not by ESP with null encryption. That's only true for IPv6. Per RFC 2402, source routing options are zeroed before calculation the AH ICV. I suggest changing "IP" to "IPv6" in that sentence. --Steve Bellovin, http://www.research.att.com/~smb