Re: [apps-discuss] apps-review team review of draft-ietf-csi-hash-threat-10

Suresh Krishnan <suresh.krishnan@ericsson.com> Mon, 18 October 2010 14:20 UTC

Return-Path: <suresh.krishnan@ericsson.com>
X-Original-To: apps-discuss@core3.amsl.com
Delivered-To: apps-discuss@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 20FFF3A6AF1 for <apps-discuss@core3.amsl.com>; Mon, 18 Oct 2010 07:20:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.519
X-Spam-Level:
X-Spam-Status: No, score=-102.519 tagged_above=-999 required=5 tests=[AWL=0.080, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tedrxRov21Tc for <apps-discuss@core3.amsl.com>; Mon, 18 Oct 2010 07:20:18 -0700 (PDT)
Received: from imr4.ericy.com (imr4.ericy.com [198.24.6.8]) by core3.amsl.com (Postfix) with ESMTP id E82443A6874 for <apps-discuss@ietf.org>; Mon, 18 Oct 2010 07:20:17 -0700 (PDT)
Received: from eusaamw0711.eamcs.ericsson.se ([147.117.20.178]) by imr4.ericy.com (8.14.3/8.14.3/Debian-9.1ubuntu1) with ESMTP id o9IEdoHZ031734; Mon, 18 Oct 2010 09:39:52 -0500
Received: from [142.133.10.113] (147.117.20.213) by eusaamw0711.eamcs.ericsson.se (147.117.20.179) with Microsoft SMTP Server id 8.2.234.1; Mon, 18 Oct 2010 10:21:35 -0400
Message-ID: <4CBC5784.8020500@ericsson.com>
Date: Mon, 18 Oct 2010 10:19:48 -0400
From: Suresh Krishnan <suresh.krishnan@ericsson.com>
User-Agent: Thunderbird 2.0.0.24 (X11/20100411)
MIME-Version: 1.0
To: Barry Leiba <barryleiba@computer.org>
References: <AANLkTikR5bcd31Rs3uTRAnf_YCEeJ=rXMzNJ6vEFqQK+@mail.gmail.com>
In-Reply-To: <AANLkTikR5bcd31Rs3uTRAnf_YCEeJ=rXMzNJ6vEFqQK+@mail.gmail.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Mailman-Approved-At: Mon, 18 Oct 2010 08:39:03 -0700
Cc: "draft-ietf-csi-hash-threat.all@tools.ietf.org" <draft-ietf-csi-hash-threat.all@tools.ietf.org>, "apps-discuss@ietf.org" <apps-discuss@ietf.org>
Subject: Re: [apps-discuss] apps-review team review of draft-ietf-csi-hash-threat-10
X-BeenThere: apps-discuss@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: General discussion of application-layer protocols <apps-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/apps-discuss>
List-Post: <mailto:apps-discuss@ietf.org>
List-Help: <mailto:apps-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 18 Oct 2010 14:20:19 -0000

Hi Barry,
   Thanks for the review.

On 10-10-16 09:09 AM, Barry Leiba wrote:
> Minor Issues:
> In section 3.3, you say "Since the structure of the Neighbor Discovery
> messages is well defined, it is not possible to use this vulnerability
> in real world attacks."  That's a strong statement, and it might be
> *possible* to find a usable hash collision, however unlikely that may
> be.  I'd say "not practical", instead.  But this is such a small point
> that it hardly matters.

Good catch. We will make this change.

Thanks
Suresh