Re: [Geopriv] [geopriv] #23: Good Security of DHCP

"James M. Polk" <jmpolk@cisco.com> Wed, 20 January 2010 05:11 UTC

Return-Path: <jmpolk@cisco.com>
X-Original-To: geopriv@core3.amsl.com
Delivered-To: geopriv@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 03CF73A692B for <geopriv@core3.amsl.com>; Tue, 19 Jan 2010 21:11:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.579
X-Spam-Level:
X-Spam-Status: No, score=-10.579 tagged_above=-999 required=5 tests=[AWL=0.020, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tUSgi-QdbsJF for <geopriv@core3.amsl.com>; Tue, 19 Jan 2010 21:11:20 -0800 (PST)
Received: from sj-iport-1.cisco.com (sj-iport-1.cisco.com [171.71.176.70]) by core3.amsl.com (Postfix) with ESMTP id E74673A6876 for <geopriv@ietf.org>; Tue, 19 Jan 2010 21:11:19 -0800 (PST)
Authentication-Results: sj-iport-1.cisco.com; dkim=neutral (message not signed) header.i=none
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: ArUEAPYeVkurR7Ht/2dsb2JhbACHBLoOlUeENgQ
X-IronPort-AV: E=Sophos;i="4.49,307,1262563200"; d="scan'208";a="290148391"
Received: from sj-core-1.cisco.com ([171.71.177.237]) by sj-iport-1.cisco.com with ESMTP; 20 Jan 2010 05:11:16 +0000
Received: from xbh-sjc-231.amer.cisco.com (xbh-sjc-231.cisco.com [128.107.191.100]) by sj-core-1.cisco.com (8.13.8/8.14.3) with ESMTP id o0K5BGiV025515; Wed, 20 Jan 2010 05:11:16 GMT
Received: from xfe-sjc-211.amer.cisco.com ([171.70.151.174]) by xbh-sjc-231.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.3959); Tue, 19 Jan 2010 21:11:16 -0800
Received: from jmpolk-wxp01.cisco.com ([10.89.2.66]) by xfe-sjc-211.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.3959); Tue, 19 Jan 2010 21:11:15 -0800
X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9
Date: Tue, 19 Jan 2010 23:11:13 -0600
To: "Thomson, Martin" <Martin.Thomson@andrew.com>, Bernard Aboba <bernard_aboba@hotmail.com>, Hannes Tschofenig <hannes.tschofenig@gmx.net>, "mlinsner@cisco.com" <mlinsner@cisco.com>
From: "James M. Polk" <jmpolk@cisco.com>
In-Reply-To: <8B0A9FCBB9832F43971E38010638454F032E44DA1C@SISPE7MB1.comms cope.com>
References: <067.d8c3c451cc0c66cb5bed185ebb0f9399@tools.ietf.org> <076.7695ce221210c0f31b26068c8a655d3b@tools.ietf.org> <XFE-SJC-2116eO6wGIa00001d39@xfe-sjc-211.amer.cisco.com> <BLU137-W28829913EC96C0E4B178BC93640@phx.gbl> <XFE-SJC-2120mmhQZiC00001bf5@xfe-sjc-212.amer.cisco.com> <8B0A9FCBB9832F43971E38010638454F032E44DA1C@SISPE7MB1.commscope.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Message-ID: <XFE-SJC-211mjuh3liW00001e1f@xfe-sjc-211.amer.cisco.com>
X-OriginalArrivalTime: 20 Jan 2010 05:11:15.0925 (UTC) FILETIME=[FDFF4050:01CA998E]
Cc: "geopriv@ietf.org" <geopriv@ietf.org>
Subject: Re: [Geopriv] [geopriv] #23: Good Security of DHCP
X-BeenThere: geopriv@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Geographic Location/Privacy <geopriv.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/geopriv>, <mailto:geopriv-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/geopriv>
List-Post: <mailto:geopriv@ietf.org>
List-Help: <mailto:geopriv-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/geopriv>, <mailto:geopriv-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Jan 2010 05:11:24 -0000

At 10:38 PM 1/19/2010, Thomson, Martin wrote:
> > >Which begs the question of what additional potential security risks
> > >the sentence is advocating that we consider.
> >
> > this might be opening up pandora's box here, so let's keep this
> > between just you and me...
> >
>
>Rather than open that box, why not close it and remove this entirely:
>
>    When implementing a DHCP server that will serve clients across an
>    uncontrolled network, one should consider the potential security
>    risks.
>
>There's sufficient specific advice already.  This doesn't really add 
>anything that can be acted upon directly; it's sort of vague.
>
> > ... you're thinking of L2 hop-by-hop,
> > or between the endhost and the first L3 node...
>
>I don't see a great deal of value in belabouring the point, unless 
>we're aware of a specific attack.  We've already highlighted the 
>disclosure problem - if the network uses hop-by-hop confidentiality, 
>then I'd hope that it would be clear that any hops can get the data.

I agree with each point made here

James


>--Martin