[113706] in North American Network Operators' Group
Re: IXP
daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Sat Apr 18 20:11:32 2009
Date: Sat, 18 Apr 2009 20:11:14 -0400
From: "Steven M. Bellovin" <smb@cs.columbia.edu>
To: Paul Vixie <vixie@isc.org>
In-Reply-To: <14911.1240089144@nsa.vix.com>
Cc: "nanog@merit.edu nanog@merit.edu" <nanog@merit.edu>
Errors-To: nanog-bounces@nanog.org
On Sat, 18 Apr 2009 21:12:24 +0000
Paul Vixie <vixie@isc.org> wrote:
> > Date: Sat, 18 Apr 2009 13:17:11 -0400
> > From: "Steven M. Bellovin" <smb@cs.columbia.edu>
> >
> > On Sat, 18 Apr 2009 16:58:24 +0000
> > bmanning@vacation.karoshi.com wrote:
> >
> > > i make the claim that simple, clean design and execution
> > > is best. even the security goofs will agree.
> >
> > "Even"? *Especially* -- or they're not competent at doing security.
>
> wouldn't a security person also know about
>
> http://en.wikipedia.org/wiki/ARP_spoofing
>
I'm taking no position on the underlying argument; I'm simply stating
that simplicity is an essential element for security. I like a
philosophy I've seen attributed to Einstein: "everything should be as
simple as possible, and no simpler".
And yes, I know about ARP spoofing...
--Steve Bellovin, http://www.cs.columbia.edu/~smb