public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Kevin Chadwick <ma1l1ists@yahoo.co.uk>
To: gentoo-user@lists.gentoo.org
Subject: Re: [Bulk] Re: [gentoo-user] /etc/hosts include file?
Date: Sat, 9 Mar 2013 12:53:04 +0000	[thread overview]
Message-ID: <205134.5515.bm@smtp151.mail.ir2.yahoo.com> (raw)
In-Reply-To: <513AAA9D.60806@gmail.com>

> "There is no reason to believe that IPv6 will result in an increased use
> of IPsec."
> 
> Bull. The biggest barrier to IPsec use has been NAT! If an intermediate
> router has to rewrite the packet to change the apparent source and/or
> destination addresses, then the cryptographic signature will show it,
> and the packet will be correctly identified as having been tampered with!
> 

It's hardly difficult to get around that now is it. You are wrong the
biggest barrier is that it is not desirable to do this as there are
many reasons for firewalls to inspect incoming packets. I don't agree
with things like central virus scanning especially by damn ISPs using
crappy Huawei hardware, deep inspection traffic shaping rather than
pure bandwidth usage tracking or active IDS myself but I do agree
with scrubbing packets.

> With IPsec, NAT is unnecessary. (You can still use it if you need
> it...but please try to avoid it!)
> 

Actually it is no problem at all and is far better than some of the
rubbish ipv6 encourages client apps to do. (See the links I sent in the
other mail)

> Re "DNS support for IPv6"
> 
> "Increased size of DNS responses due to larger addresses might be
> exploited for DDos attacks"
> 
> That's not even significant. Have you looked at the size of DNS
> responses? The increased size of the address pales in comparison to the
> amount of other data already stuffed into the packet.

It's been ages since I looked at that link and longer addresses would
certainly be needed anyway but certainly with DNSSEC again concocted by
costly unthoughtful and unengaging groups who chose to ignore DJB
and enable amplification attacks.

His latest on the "DNS security mess"

http://cr.yp.to/talks/2013.02.07/slides.pdf

> "An attacker can connect to an IPv4-only network, and forge IPv6 Router
> Advertisement messages. (*)"

> Again, this depends on them being on the same layer 2 network segment.

> The same class of attacks would be possible for any IPv4 successor that
> implemented either RAs or DHCP.

Neither of which I use.

As I said we would be here all day and that link wasn't as good as the
one I was actually looking for.

local NAT done right is no problem and actually a good thing and I have
no issues playing games, running servers or anything else behind NAT.
Global NAT works well enough but isn't a good thing and wouldn't exist
if they had simply added more addresses quickly. The hardware uptake
would have been no issue rather than a decade of pleads.

We haven't even touched on the code yet and so all the vulnerable
especially home hardware which yes often has vulnerable sps anyway but
by no way just home hardware.

The ipvshit links give an insight into the code complexity. Note
OpenBSDs kernel which is very secure (unlike Linux whose primary goal is
function) and has had just a few remote holes in well over a decade, one
of which was in ipv6 and which I had avoided without down time because I
won't and what's more shouldn't use ipv6 wherever possible and had
actually removed it from the kernel all together.

If I am Trolling rather than simply trying to make people aware then
stating ipv6 is wonderful is Trolling just as much or more.

Regards,
	Kc

-- 
_______________________________________________________________________

'Write programs that do one thing and do it well. Write programs to work
together. Write programs to handle text streams, because that is a
universal interface'

(Doug McIlroy)
_______________________________________________________________________


  reply	other threads:[~2013-03-09 12:55 UTC|newest]

Thread overview: 48+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-03-07 22:24 [gentoo-user] /etc/hosts include file? Alan McKinnon
2013-03-07 23:50 ` Michael Mol
2013-03-08  0:29 ` Michael Mol
2013-03-08  8:32   ` Alan McKinnon
2013-03-08 13:40     ` Michael Mol
2013-03-08 13:54       ` Alan McKinnon
2013-03-08 19:50         ` [Bulk] " Kevin Chadwick
2013-03-08 19:55           ` Michael Mol
2013-03-08 21:49             ` Kevin Chadwick
2013-03-08 22:36               ` Pandu Poluan
2013-03-09  0:50                 ` Kevin Chadwick
2013-03-09  3:27                   ` Michael Mol
2013-03-09 12:53                     ` Kevin Chadwick
2013-03-10 21:28                       ` Michael Mol
2013-03-11 23:09                         ` Kevin Chadwick
2013-03-12  5:05                           ` Michael Mol
2013-03-09  0:13               ` Walter Dnes
2013-03-09  0:41                 ` Michael Mol
2013-03-10  1:42                   ` Walter Dnes
2013-03-10  4:59                     ` Michael Orlitzky
2013-03-10 21:09                       ` Michael Mol
2013-03-10  5:19                     ` Alan McKinnon
2013-03-10 21:07                       ` Michael Mol
2013-03-10 21:43                         ` Alan McKinnon
2013-03-10 22:02                           ` Michael Mol
2013-03-11  4:00                         ` Walter Dnes
2013-03-11  4:37                           ` Michael Mol
2013-03-11  8:22                           ` Alan McKinnon
2013-03-11 22:45                             ` Walter Dnes
2013-03-11 23:39                               ` Kevin Chadwick
2013-03-12  3:58                                 ` Walter Dnes
2013-03-12  0:25                               ` Alan McKinnon
2013-03-12  2:02                               ` Michael Mol
2013-03-12 11:29                                 ` Alan McKinnon
2013-03-13  0:26                                   ` [Bulk] " Kevin Chadwick
2013-03-11 23:31                             ` Kevin Chadwick
2013-03-12  0:37                               ` Alan McKinnon
2013-03-09  0:45                 ` Kevin Chadwick
2013-03-09  3:21                   ` Michael Mol
2013-03-09 12:53                     ` Kevin Chadwick [this message]
2013-03-10 22:00                       ` Michael Mol
2013-03-11  1:56                         ` Michael Orlitzky
2013-03-11  2:33                           ` Michael Mol
2013-03-11 22:34                         ` Kevin Chadwick
2013-03-12  3:36                           ` Michael Mol
2013-03-08 15:39   ` Florian Philipp
2013-03-08  4:30 ` Pandu Poluan
2013-03-08  8:23   ` Alan McKinnon

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=205134.5515.bm@smtp151.mail.ir2.yahoo.com \
    --to=ma1l1ists@yahoo.co.uk \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox