[149053] in North American Network Operators' Group
Re: MD5 considered harmful
daemon@ATHENA.MIT.EDU (Christopher Morrow)
Fri Jan 27 16:22:13 2012
In-Reply-To: <0B6DEEFE-0049-4223-BB76-4A6A52D929E2@ianai.net>
Date: Fri, 27 Jan 2012 16:21:49 -0500
From: Christopher Morrow <morrowc.lists@gmail.com>
To: "Patrick W. Gilmore" <patrick@ianai.net>
Cc: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Fri, Jan 27, 2012 at 3:52 PM, Patrick W. Gilmore <patrick@ianai.net> wro=
te:
> MD5 on BGP sessions is the canonical example of a cure worse than the dis=
ease. =A0There has been /infinitely/ more downtime caused by MD5 than the m=
ythical attack it protects again. =A0(This is true because anything times z=
ero is still zero.)
>
I don't disagree with patrick here... but 'infinitely more', is hard
to measure :) "Most likely there have been far more lengthy outages
due to lost/changed/incorrect key material than were caused by the
problem this is meant to solve for."
-chris
> It is