Re: Pseudorandom Flow Labels

Fernando Gont <fernando@gont.com.ar> Wed, 06 April 2011 21:20 UTC

Return-Path: <fernando.gont.netbook.win@gmail.com>
X-Original-To: ipv6@core3.amsl.com
Delivered-To: ipv6@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 59AF43A6956 for <ipv6@core3.amsl.com>; Wed, 6 Apr 2011 14:20:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.599
X-Spam-Level:
X-Spam-Status: No, score=-3.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CVz+CEi-oNLP for <ipv6@core3.amsl.com>; Wed, 6 Apr 2011 14:20:27 -0700 (PDT)
Received: from mail-gw0-f44.google.com (mail-gw0-f44.google.com [74.125.83.44]) by core3.amsl.com (Postfix) with ESMTP id 9460A3A67D3 for <ipv6@ietf.org>; Wed, 6 Apr 2011 14:20:27 -0700 (PDT)
Received: by gwb20 with SMTP id 20so670437gwb.31 for <ipv6@ietf.org>; Wed, 06 Apr 2011 14:22:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:sender:message-id:date:from:user-agent :mime-version:to:cc:subject:references:in-reply-to :x-enigmail-version:openpgp:content-type:content-transfer-encoding; bh=iGVwclmMeZ7ntcabJXTfND1KUD7wKA43Aae353+UI7U=; b=SmdRDwAwypESQzQ2SIAIEnrKzCMryPY4a3OE3XmTLuMdh/LUiX2rIWNXK9/tvGwBxN uiTTKYb5oxaQhaYzfIq/UEGEQVXzOZk7ITN/veMOAFvUuHzg9e0JBgfBahDZF/VPQ/ds iW7PVJ5b6HSEsqxbxVGt5f9scwDuejoC4nNMc=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=sender:message-id:date:from:user-agent:mime-version:to:cc:subject :references:in-reply-to:x-enigmail-version:openpgp:content-type :content-transfer-encoding; b=DmhBLelL7qvcr7U+5lusHX03hgkI/TK/Dq0YlpY3JGbph3U8STQ8OuEPxyil2eqKZV lYruWSHuhpvO/eDCcITbdiY3UA9Ng+uIZGP4J2oRshivFL9E2Q4KKsNyrhois3ZBQNu1 TyKORVfVl6paDf2ZZrSq9qLLAETCsgCOKj2mU=
Received: by 10.236.77.97 with SMTP id c61mr122401yhe.297.1302124931094; Wed, 06 Apr 2011 14:22:11 -0700 (PDT)
Received: from [192.168.123.101] ([190.48.201.131]) by mx.google.com with ESMTPS id c17sm1065743anc.41.2011.04.06.14.22.08 (version=TLSv1/SSLv3 cipher=OTHER); Wed, 06 Apr 2011 14:22:10 -0700 (PDT)
Sender: Fernando Gont <fernando.gont.netbook.win@gmail.com>
Message-ID: <4D9CD97D.1060208@gont.com.ar>
Date: Wed, 06 Apr 2011 18:22:05 -0300
From: Fernando Gont <fernando@gont.com.ar>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: John Leslie <john@jlc.net>
Subject: Re: Pseudorandom Flow Labels
References: <BD901061-96AC-4915-B7CE-2BC1F70861A5@castlepoint.net> <201104052036.p35KaoHV019253@cichlid.raleigh.ibm.com> <4D9CAF52.9050805@gont.com.ar> <20110406204424.GG24474@verdi>
In-Reply-To: <20110406204424.GG24474@verdi>
X-Enigmail-Version: 1.1.1
OpenPGP: id=D076FFF1
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Cc: 6man List <ipv6@ietf.org>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ipv6>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Apr 2011 21:20:28 -0000

John,

On 06/04/2011 05:44 p.m., John Leslie wrote:
> Fernando Gont <fernando@gont.com.ar> wrote:
>> * We want Flow Labels that unpredictable by off-path attackers (history
>>   has taught us that this is a good proactive measure)
> 
>    I'm afraid I don't follow: what sort of attack could an off-path
> attacker mount by correctly guessing the Flow Label?

Play with ECMP/LAG. And, it's clear you could never implement something
like draft-blake-ipv6-flow-label-nonce-02 if FLs are predictable.

Thanks,
-- 
Fernando Gont
e-mail: fernando@gont.com.ar || fgont@acm.org
PGP Fingerprint: 7809 84F5 322E 45C7 F1C9 3945 96EE A9EF D076 FFF1