[134416] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: NIST IPv6 document

daemon@ATHENA.MIT.EDU (Dobbins, Roland)
Wed Jan 5 22:20:05 2011

From: "Dobbins, Roland" <rdobbins@arbor.net>
To: Nanog Operators' Group <nanog@nanog.org>
Date: Thu, 6 Jan 2011 03:18:52 +0000
In-Reply-To: <201101060308.p0638wha085757@aurora.sol.net>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Jan 6, 2011, at 10:08 AM, Joe Greco wrote:

> Packing everything densely is an obvious problem with IPv4; we learned ea=
rly on that having a 48-bit (32 address, 16 port) space to scan made
> port-scanning easy, attractive, productive, and commonplace.

I don't believe that host-/port-scanning is as serious a problem as you see=
m to think it is, nor do I think that trying to somehow prevent host from b=
eing host-/port-scanned has any material benefit in terms of security postu=
re, that's our fundamental disagreement.

If I've done what's necessary to secure my hosts/applications, host-/port-s=
canning isn't going to find anything to exploit (overly-aggressive scanning=
 can be a DoS vector, but there are ways to ameliorate that, too).

If I haven't done what's necessary to secure my hosts/applications, one way=
 or another, they *will* end up being exploited - and the faux security-by-=
obscurity offered by sparse addressing won't matter a bit.

This whole focus on sparse addressing is just another way to tout security-=
by-obscurity.  We already know that security-by-obscurity is a fundamentall=
y-flawed concept, so it doesn't make sense to try and keep rationalizing it=
 in various domain-specific instantiations.

------------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>

Most software today is very much like an Egyptian pyramid, with millions
of bricks piled on top of each other, with no structural integrity, but
just done by brute force and thousands of slaves.

			  -- Alan Kay



home help back first fref pref prev next nref lref last post