[178899] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

RE: Searching for a quote

daemon@ATHENA.MIT.EDU (Keith Medcalf)
Fri Mar 13 01:26:04 2015

X-Original-To: nanog@nanog.org
Date: Thu, 12 Mar 2015 23:25:58 -0600
In-Reply-To: <55022FFA.1030309@mtcc.com>
From: "Keith Medcalf" <kmedcalf@dessus.com>
To: "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org


Robustness is desirable from a security perspective.  Failure to be liberal=
 in what you accept and not being prepared to deal with malformed input lea=
ds to such wonders as the Microsoft bug that led to unexpected/malformed IP=
 datagrams mishandled as "execute payload with system authority".  Rather t=
han sloppiness you could also attribute the error to malice -- that it was =
injected at the specific request of certain government agencies, perhaps un=
der threat, perhaps with just a wink and a nod ...

---
Theory is when you know everything but nothing works.  Practice is when eve=
rything works but no one knows why.  Sometimes theory and practice are comb=
ined:  nothing works and no one knows why.


>-----Original Message-----
>From: NANOG [mailto:nanog-bounces@nanog.org] On Behalf Of Michael Thomas
>Sent: Thursday, 12 March, 2015 18:32
>To: nanog@nanog.org
>Subject: Re: Searching for a quote
>
>Jon Postel. I'm told that it is out of favor these days in protocol-land,
>from a security standpoint if nothing else.
>
>Mike
>
>On 3/12/15 5:24 PM, Tom Paseka wrote:
>> Be conservative in what you send, be liberal in what you accept
>>
>> ^http://en.wikipedia.org/wiki/Robustness_principle
>>
>> On Thu, Mar 12, 2015 at 5:20 PM, Jason Iannone
><jason.iannone@gmail.com>
>> wrote:
>>
>>> There was once a fairly common saying attributed to an early
>>> networking pioneer that went something like, "be generous in what you
>>> accept, and send only the stuff that should be sent."  Does anyone
>>> know what I'm talking about or who said it?
>>>





home help back first fref pref prev next nref lref last post