Re: [dnssd] Security through Obscurity

Michael Richardson <mcr@sandelman.ca> Thu, 24 July 2014 19:09 UTC

Return-Path: <mcr@sandelman.ca>
X-Original-To: dnssd@ietfa.amsl.com
Delivered-To: dnssd@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 708411A002A for <dnssd@ietfa.amsl.com>; Thu, 24 Jul 2014 12:09:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.881
X-Spam-Level:
X-Spam-Status: No, score=-0.881 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, MISSING_HEADERS=1.021, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 19ZgKKodE5m3 for <dnssd@ietfa.amsl.com>; Thu, 24 Jul 2014 12:09:27 -0700 (PDT)
Received: from tuna.sandelman.ca (tuna.sandelman.ca [IPv6:2607:f0b0:f:3:216:3eff:fe7c:d1f3]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1B01A1B2830 for <dnssd@ietf.org>; Thu, 24 Jul 2014 12:08:50 -0700 (PDT)
Received: from sandelman.ca (obiwan.sandelman.ca [IPv6:2607:f0b0:f:2::247]) by tuna.sandelman.ca (Postfix) with ESMTP id 9766920012 for <dnssd@ietf.org>; Thu, 24 Jul 2014 15:10:34 -0400 (EDT)
Received: by sandelman.ca (Postfix, from userid 179) id 2FBB563B0E; Thu, 24 Jul 2014 15:08:48 -0400 (EDT)
Received: from sandelman.ca (localhost [127.0.0.1]) by sandelman.ca (Postfix) with ESMTP id 160F663B0A for <dnssd@ietf.org>; Thu, 24 Jul 2014 15:08:48 -0400 (EDT)
From: Michael Richardson <mcr@sandelman.ca>
cc: dnssd@ietf.org
In-Reply-To: <24377.1406225491@sandelman.ca>
References: <0644A943-80B9-42E0-BF82-3E1113710FA2@gmail.com> <20E4ED19-12BD-45D4-B690-8629B552B23B@gmail.com> <0E0BC226-E68E-4BC2-99EA-AFF1AF96A5EC@ecs.soton.ac.uk> <EMEW3|faec94f4ff05bea449f9614b93dae254q6NE8Q03tjc|ecs.soton.ac.uk|0E0BC226-E68E-4BC2-99EA-AFF1AF96A5EC@ecs.soton.ac.uk> <E6F68BE4-7094-45AA-ADD9-4B88BBC87921@gmail.com> <8465FD60-84CD-41B3-BBE3-1BDB52DF0DDB@hp.com> <364AAF85-5FB4-4828-A5A4-11160E747BC9@gmail.com> <24377.1406225491@sandelman.ca>
X-Mailer: MH-E 8.2; nmh 1.3-dev; GNU Emacs 23.4.1
X-Face: $\n1pF)h^`}$H>Hk{L"x@)JS7<%Az}5RyS@k9X%29-lHB$Ti.V>2bi.~ehC0; <'$9xN5Ub# z!G,p`nR&p7Fz@^UXIn156S8.~^@MJ*mMsD7=QFeq%AL4m<nPbLgmtKK-5dC@#:k
Date: Thu, 24 Jul 2014 15:08:48 -0400
Message-ID: <3949.1406228928@sandelman.ca>
Sender: mcr@sandelman.ca
Archived-At: http://mailarchive.ietf.org/arch/msg/dnssd/UOm60pMLvjk_P16TZKype8RFzLE
Subject: Re: [dnssd] Security through Obscurity
X-BeenThere: dnssd@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussion of extensions to Bonjour \(mDNS and DNS-SD\) for routed networks." <dnssd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnssd>, <mailto:dnssd-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnssd/>
List-Post: <mailto:dnssd@ietf.org>
List-Help: <mailto:dnssd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnssd>, <mailto:dnssd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Jul 2014 19:09:28 -0000

RJ Atkinson <rja.lists@gmail.com> wrote:
    > The most common reason that my clients give me is that
    > predictable/deterministic IP addressing lowers their
    > operating costs.  Larger enterprises often use DHCP
    > to obtain this.  Smaller enterprises find DHCP complex
    > to deploy/configure, but they still want predictable
    > addressing in their IP network deployments.

Three printers on the floor.
One is reporting it is broken, so broken that you can't do much more than
see that it exists.
If the IP(v6) address is predictable, and related in some way to the
EUI-64, then you can find the right unit.
The printer has little privacy concerns, seldom visits internet cafes,
and is never found it airport lounges.

--
]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        | network architect  [
]     mcr@sandelman.ca  http://www.sandelman.ca/        |   ruby on rails    [