From owner-freebsd-net@FreeBSD.ORG Fri Mar 11 04:06:00 2005 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D45E616A4CE for ; Fri, 11 Mar 2005 04:06:00 +0000 (GMT) Received: from outbound0.sv.meer.net (outbound0.sv.meer.net [205.217.152.13]) by mx1.FreeBSD.org (Postfix) with ESMTP id 288A443D5A for ; Fri, 11 Mar 2005 04:06:00 +0000 (GMT) (envelope-from gnn@neville-neil.com) Received: from mail.meer.net (mail.meer.net [209.157.152.14]) j2B45wV1033454; Thu, 10 Mar 2005 20:05:58 -0800 (PST) (envelope-from gnn@neville-neil.com) Received: from minion.local.neville-neil.com (pc1.oakwoodazabu1-unet.ocn.ne.jp [220.110.140.201]) by mail.meer.net (8.12.10/8.12.10/meer) with ESMTP id j2B45suG088225; Thu, 10 Mar 2005 20:05:55 -0800 (PST) (envelope-from gnn@neville-neil.com) Date: Fri, 11 Mar 2005 13:05:52 +0900 Message-ID: From: gnn@freebsd.org To: Anthony Atkielski In-Reply-To: <771770969.20050311034646@wanadoo.fr> References: <771770969.20050311034646@wanadoo.fr> User-Agent: Wanderlust/2.12.0 (Your Wildest Dreams) SEMI/1.14.6 (Maruoka) FLIM/1.14.6 (Marutamachi) APEL/10.6 Emacs/21.3.50 (powerpc-apple-darwin7.7.0) MULE/5.0 (SAKAKI) MIME-Version: 1.0 (generated by SEMI 1.14.6 - "Maruoka") Content-Type: text/plain; charset=US-ASCII cc: freebsd-net@freebsd.org Subject: Re: Clock slew vulnerability in FreeBSD? X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 11 Mar 2005 04:06:01 -0000 At Fri, 11 Mar 2005 03:46:46 +0100, Anthony Atkielski wrote: > > > How vulnerable is FreeBSD to the recently announced technique for > individually identifying computers by the clock slew apparent in TCP > packets? If it is vulnerable to this, will there be any plans to > address the vulnerability? > I gather you mean this paper: http://www.caida.org/outreach/papers/2005/fingerprinting/ It's an interesting read. As to how vulnerable FreeBSD is to this I do not know nor do I know if we should bother to do anything about it. What, in particular are you worried about here? Also, if you consider this a security issue you should probably also include the security team in this discussion. Later, George