Re: [v6ops] [IPv6] Why folks are blocking IPv6 extension headers? (Episode 1000 and counting) (Linux DoS)

Fernando Gont <fgont@si6networks.com> Thu, 18 May 2023 13:17 UTC

Return-Path: <fgont@si6networks.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AC75AC151981; Thu, 18 May 2023 06:17:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y6DlksnksfKk; Thu, 18 May 2023 06:17:23 -0700 (PDT)
Received: from fgont.go6lab.si (fgont.go6lab.si [IPv6:2001:67c:27e4::14]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EE7A3C151980; Thu, 18 May 2023 06:17:20 -0700 (PDT)
Received: from [172.19.0.3] (149.104.176.34.bc.googleusercontent.com [34.176.104.149]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by fgont.go6lab.si (Postfix) with ESMTPSA id D0C592803F1; Thu, 18 May 2023 10:17:13 -0300 (-03)
Message-ID: <a087b963-1e12-66bf-b93e-5190ce09914b@si6networks.com>
Date: Thu, 18 May 2023 15:17:09 +0200
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.10.0
Content-Language: en-US
To: David Farmer <farmer@umn.edu>, Tom Herbert <tom=40herbertland.com@dmarc.ietf.org>
Cc: 6man@ietf.org, V6 Ops List <v6ops@ietf.org>, opsec WG <opsec@ietf.org>
References: <11087a11-476c-5fb8-2ede-e1b3b6e95e48@si6networks.com> <CALx6S343f_FPXVxuZuXB4j=nY-SuTEYrnxb3O5OQ3fv5uPwT8g@mail.gmail.com> <CAN-Dau1pTVr6ak9rc9x7irg+aLhq0N8_WOyySqx5Syt74HMX=g@mail.gmail.com>
From: Fernando Gont <fgont@si6networks.com>
Organization: SI6 Networks
In-Reply-To: <CAN-Dau1pTVr6ak9rc9x7irg+aLhq0N8_WOyySqx5Syt74HMX=g@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/6w6sWK6ToKNeRgZiZ49GZPeo_yU>
Subject: Re: [v6ops] [IPv6] Why folks are blocking IPv6 extension headers? (Episode 1000 and counting) (Linux DoS)
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 May 2023 13:17:24 -0000

Hi, David,

On 18/5/23 02:14, David Farmer wrote:
> 
> 
> On Wed, May 17, 2023 at 13:57 Tom Herbert 
> <tom=40herbertland.com@dmarc.ietf.org 
> <mailto:40herbertland.com@dmarc.ietf.org>> wrote:
[...]
> 
> Maximum security is rarely the objective, I by no means have maximum 
> security at my home. However, I don’t live in the country where some 
> people still don’t even lock there doors. I live in a a city, I have 
> decent deadbolt locks and I use them.
> 
[....]
> 
> So, I’m not really happy with the all or nothing approach the two of you 
> seem to be offering for IPv6 extension headers, is there something in 
> between? If not, then maybe that is what we need to be working towards.

FWIW, I[m not arguing for a blank "block all", but rather "just allow 
the ones you really need" -- which is a no brainer. The list you need 
is, maybe Frag and, say, IPsec at the global level? (from the pov of 
most orgs).

(yeah... HbH and the like are mostly fine for the local link (e.g. MLD).

Thanks,
-- 
Fernando Gont
SI6 Networks
e-mail: fgont@si6networks.com
PGP Fingerprint: F242 FF0E A804 AF81 EB10 2F07 7CA1 321D 663B B494