Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 5 Mar 2008 15:26:32 -0800
From:      "Peter Wemm" <peter@wemm.org>
To:        "Brandon S. Allbery KF8NH" <allbery@ece.cmu.edu>
Cc:        Vadim Goncharov <vadim_nuclight@mail.ru>, Jeremy Chadwick <koitsu@freebsd.org>, Mark Andrews <Mark_Andrews@isc.org>, FreeBSD Stable <freebsd-stable@freebsd.org>
Subject:   Re: INET6 -- and why I don't use it
Message-ID:  <e7db6d980803051526r69d957c3uf98e050d441e86c8@mail.gmail.com>
In-Reply-To: <87800D7B-3866-4FC0-B757-BF2AB808920E@ece.cmu.edu>
References:  <200803052231.m25MVl0p066992@drugs.dv.isc.org> <87800D7B-3866-4FC0-B757-BF2AB808920E@ece.cmu.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Mar 5, 2008 at 2:44 PM, Brandon S. Allbery KF8NH
<allbery@ece.cmu.edu> wrote:
>
>  On Mar 5, 2008, at 17:31 , Mark Andrews wrote:
>  >
>  >> On Wed, Mar 05, 2008 at 03:00:29PM +0000, Vadim Goncharov wrote:
>
> >>> * The last I read about IPv6 in mainstream news, there were major
>  >> concerns cited over some of the security aspects of the protocol.  I
>  >> also remember reading somewhere that IPv6 was supposed to address
>  >> issues
>  >> like packet spoofing and DoS -- what became of this?
>  >
>  >       Someone was feeding you a load of horse @$$!.
>
>  When Marcus Ranum is one of those questioning its security, I'm
>  inclined to believe him.  (Google "mjr ipv6 security" --- his point
>  in a nutshell is that we're going to be fixing old IPv4 holes in new
>  guises for a while.)

IPv6 has got enough rope (features) that you can hang yourself in most
of the same ways as ipv4.  If anything, these 'enhanced' versions of
ipv4 features give you new and exquisitely delicious ways of screwing
yourself.

eg: You can do the same kinds of damage with source routing in both
ipv4 and ipv6 when it is enabled.  OS developers can make the same
mistakes parsing options in both.  And so on.  (Who remembers the ipv4
'ping of death' in the early 90's?  you could send a packet with a
zero-length option to random hosts and instantly kill them)
-- 
Peter Wemm - peter@wemm.org; peter@FreeBSD.org; peter@yahoo-inc.com
"All of this is for nothing if we don't go to the stars" - JMS/B5
"If Java had true garbage collection, most programs would delete
themselves upon execution." -- Robert Sewell



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?e7db6d980803051526r69d957c3uf98e050d441e86c8>