[113706] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IXP

daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Sat Apr 18 20:11:32 2009

Date: Sat, 18 Apr 2009 20:11:14 -0400
From: "Steven M. Bellovin" <smb@cs.columbia.edu>
To: Paul Vixie <vixie@isc.org>
In-Reply-To: <14911.1240089144@nsa.vix.com>
Cc: "nanog@merit.edu nanog@merit.edu" <nanog@merit.edu>
Errors-To: nanog-bounces@nanog.org

On Sat, 18 Apr 2009 21:12:24 +0000
Paul Vixie <vixie@isc.org> wrote:

> > Date: Sat, 18 Apr 2009 13:17:11 -0400
> > From: "Steven M. Bellovin" <smb@cs.columbia.edu>
> > 
> > On Sat, 18 Apr 2009 16:58:24 +0000
> > bmanning@vacation.karoshi.com wrote:
> > 
> > > 	i make the claim that simple, clean design and execution
> > > is best. even the security goofs will agree.   
> >
> > "Even"?  *Especially* -- or they're not competent at doing security.
> 
> wouldn't a security person also know about
> 
> 	http://en.wikipedia.org/wiki/ARP_spoofing
> 
I'm taking no position on the underlying argument; I'm simply stating
that simplicity is an essential element for security.  I like a
philosophy I've seen attributed to Einstein: "everything should be as
simple as possible, and no simpler".

And yes, I know about ARP spoofing...


		--Steve Bellovin, http://www.cs.columbia.edu/~smb


home help back first fref pref prev next nref lref last post