Re: [homenet] Please review security considerations of draft-homenet-babel-profile

Philip Homburg <pch-homenet-3@u-1.phicoh.com> Wed, 26 July 2017 09:47 UTC

Return-Path: <pch-b7900FA3D@u-1.phicoh.com>
X-Original-To: homenet@ietfa.amsl.com
Delivered-To: homenet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3DBD81318A2 for <homenet@ietfa.amsl.com>; Wed, 26 Jul 2017 02:47:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r_idpS437dI8 for <homenet@ietfa.amsl.com>; Wed, 26 Jul 2017 02:47:03 -0700 (PDT)
Received: from stereo.hq.phicoh.net (stereo6-tun.hq.phicoh.net [IPv6:2001:888:1044:10:2a0:c9ff:fe9f:17a9]) by ietfa.amsl.com (Postfix) with ESMTP id EFFB1131947 for <homenet@ietf.org>; Wed, 26 Jul 2017 02:47:02 -0700 (PDT)
Received: from stereo.hq.phicoh.net (localhost [::ffff:127.0.0.1]) by stereo.hq.phicoh.net with esmtp (Smail #130) id m1daIuD-0000IGC; Wed, 26 Jul 2017 11:47:01 +0200
Message-Id: <m1daIuD-0000IGC@stereo.hq.phicoh.net>
To: homenet@ietf.org
Cc: Juliusz Chroboczek <jch@irif.fr>
From: Philip Homburg <pch-homenet-3@u-1.phicoh.com>
Sender: pch-b7900FA3D@u-1.phicoh.com
In-reply-to: Your message of "Tue, 25 Jul 2017 22:27:19 +0200 ." <874lu045zs.wl-jch@irif.fr>
Date: Wed, 26 Jul 2017 11:47:01 +0200
Archived-At: <https://mailarchive.ietf.org/arch/msg/homenet/smsekpwvU0nmTCTKCpvnStjfWdE>
Subject: Re: [homenet] Please review security considerations of draft-homenet-babel-profile
X-BeenThere: homenet@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF Homenet WG mailing list <homenet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/homenet>, <mailto:homenet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/homenet/>
List-Post: <mailto:homenet@ietf.org>
List-Help: <mailto:homenet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/homenet>, <mailto:homenet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Jul 2017 09:47:05 -0000

>Nasty comments on list, please, compliments by private mail ;-)

A trick used in some places, such as ND, is to require the receiver to check
that the hop limit is equal to 255. This ensures that the packet has not
been forwarded by any router (obviously the sender also has to send it with
a hop limit of 255).

Historically, a popular brand of router would forward packets with LL source.
So that cannot be considered safe in general.