Re: [dhcwg] [Int-area] BoF and Non-WG Mailing List: madinas -- MAC Address Device Identification for Network and Application Services

Carsten Bormann <cabo@tzi.org> Mon, 02 November 2020 07:20 UTC

Return-Path: <cabo@tzi.org>
X-Original-To: dhcwg@ietfa.amsl.com
Delivered-To: dhcwg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 134343A0147; Sun, 1 Nov 2020 23:20:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xRj-xUQxYe5Q; Sun, 1 Nov 2020 23:20:55 -0800 (PST)
Received: from gabriel-vm-2.zfn.uni-bremen.de (gabriel-vm-2.zfn.uni-bremen.de [134.102.50.17]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BAAE33A0140; Sun, 1 Nov 2020 23:20:54 -0800 (PST)
Received: from [192.168.217.118] (p548dcc60.dip0.t-ipconnect.de [84.141.204.96]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by gabriel-vm-2.zfn.uni-bremen.de (Postfix) with ESMTPSA id 4CPkpr3KywzySb; Mon, 2 Nov 2020 08:20:52 +0100 (CET)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.120.23.2.4\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <CAHLBt83DN3OxhXbkFKPBh7KbPFvKJKjgdf5UfoGVSsTJh6+H=Q@mail.gmail.com>
Date: Mon, 02 Nov 2020 08:20:51 +0100
Cc: int-area@ietf.org, dhcwg@ietf.org
X-Mao-Original-Outgoing-Id: 625994451.6692359-569d67f55ff90777b1d7183cd71dfcbb
Reply-To: madinas@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <E37B8383-CAD6-4D57-BDB4-E7170F3EAE63@tzi.org>
References: <160407478723.4708.16590139659517606146@ietfa.amsl.com> <CAHLBt83DN3OxhXbkFKPBh7KbPFvKJKjgdf5UfoGVSsTJh6+H=Q@mail.gmail.com>
To: madinas@ietf.org
X-Mailer: Apple Mail (2.3608.120.23.2.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/dhcwg/Sd6JpnDj62_-YUcnUx5oMTG6UwM>
Subject: Re: [dhcwg] [Int-area] BoF and Non-WG Mailing List: madinas -- MAC Address Device Identification for Network and Application Services
X-BeenThere: dhcwg@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <dhcwg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dhcwg/>
List-Post: <mailto:dhcwg@ietf.org>
List-Help: <mailto:dhcwg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dhcwg>, <mailto:dhcwg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 Nov 2020 07:20:58 -0000

On 2020-11-01, at 22:56, Juan Carlos Zuniga <j.c.zuniga@ieee.org> wrote:
> 
> https://github.com/jlivingood/IETF109BoF/blob/master/109-Agenda.md

I don’t understand the slides about home device MAC addresses, https://github.com/boucadair/IETF109BoF/blob/master/madinas-ddos%20mitigation-use%20case-rev%2027102020.pdf

If mitigations are widely deployed that are based on MAC address filtering, attackers will implement countermeasures (such as varying the MAC address quickly enough to defeat the mitigation signaling).  MAC address randomization as implemented by a device vendor would probably be too slow as a countermeasure (if it were, it would save the attacker a little work, but not that much).

(Please reply to madinas@ietf.org.)

Grüße, Carsten