Re: [v6ops] [IPv6] [OPSEC] Why folks are blocking IPv 6 extension headers? (Episode 1000 and counting) (Linux DoS)

Tom Herbert <tom@herbertland.com> Fri, 26 May 2023 21:37 UTC

Return-Path: <tom@herbertland.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EF022C14CE2B for <v6ops@ietfa.amsl.com>; Fri, 26 May 2023 14:37:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.097
X-Spam-Level:
X-Spam-Status: No, score=-7.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=herbertland.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aYpaKr4lZPnI for <v6ops@ietfa.amsl.com>; Fri, 26 May 2023 14:37:18 -0700 (PDT)
Received: from mail-pf1-x431.google.com (mail-pf1-x431.google.com [IPv6:2607:f8b0:4864:20::431]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F0AD2C14CEE3 for <v6ops@ietf.org>; Fri, 26 May 2023 14:37:18 -0700 (PDT)
Received: by mail-pf1-x431.google.com with SMTP id d2e1a72fcca58-64d2c865e4eso1134224b3a.0 for <v6ops@ietf.org>; Fri, 26 May 2023 14:37:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=herbertland.com; s=google; t=1685137038; x=1687729038; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=ryOSN3Fh83gd2ph8Ak7FfkBb4QvKj9u/TV8LS+XHmhE=; b=Oin+gIfan/cQsCRjCn9h3zqEYYLqyeZRdwv+pOXW91i8NPsekRyjDQ71af1vDkN9+M Lf1sKHBBeMW7tTzzaYUYwbyXeBEHP6ftqU9Grs+sEdKaEb4+ymbwqXDVt7K9IvzBzqrx AnnRl/kKT11384zobIIdbbDdf47An8yjOlRH9Z8GYfdXV/hQ/zQn5n0aKpU19AIlroT7 OnCfEX6M4eAPpp/pw8agYTJhMs4EnK8EgANHaiWtTnUZL+eVv/OEgSDRqIyJnu8qO44R pfJSbRxCTb5XyuSNrBzmVstsSVuSgS6oliN4QrGD4+br5oBce0nDEUp2yT14nkgp+7rH y97A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20221208; t=1685137038; x=1687729038; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=ryOSN3Fh83gd2ph8Ak7FfkBb4QvKj9u/TV8LS+XHmhE=; b=BkCxpo+TaRyHVY/gvrUG5/MQxFndnZNrgrxrxeZZ759WpdoNKVwRteGQU/yKZeoQv4 UOfewwkleWDbAd6Xp2BK2kP0YcUr+Pvq1w50ooS45FVCryT2JkIpjuS01MLiaq2nPjFm AlmzBOgSUm7A8L3EJfRTD8JZ1zbnD/DVSTuQHhQex+bgqYWvUCjO0vQWkGlsgASJVwzy YnJpPhfYA85HwoiHRw5q0IR/EsplkXBotq0XTKb7E3INxxaT/QpGnWt4IKdMyWfna346 7tp7rvTSDme8FUpDfSuLjcqTfpiPU0Z6r99ziYEj1Ijx94gLxT95An6fd9hXRyEKxsCy LYKw==
X-Gm-Message-State: AC+VfDywk3GjtFSIGflhck59dD1wgydTVtna+sKG+RY6yWdS61tPBsuE RUpyRI78MbmST5e3WouGKk87iTICE2Xu5lBLbVt/HA==
X-Google-Smtp-Source: ACHHUZ6Vb5tfn/qa7u1Hre5dNRYt48HI8DAiyaJL2Y4wS0CiQLE35KgAoZDvwyzz5+f6EWgC1VT00ELAfBhd6dVOhQ0=
X-Received: by 2002:a05:6a20:728c:b0:10f:13bb:5d4f with SMTP id o12-20020a056a20728c00b0010f13bb5d4fmr1004935pzk.2.1685137038168; Fri, 26 May 2023 14:37:18 -0700 (PDT)
MIME-Version: 1.0
References: <11087a11-476c-5fb8-2ede-e1b3b6e95e48@si6networks.com> <CALx6S343f_FPXVxuZuXB4j=nY-SuTEYrnxb3O5OQ3fv5uPwT8g@mail.gmail.com> <CAN-Dau1pTVr6ak9rc9x7irg+aLhq0N8_WOyySqx5Syt74HMX=g@mail.gmail.com> <a087b963-1e12-66bf-b93e-5190ce09914b@si6networks.com> <CALx6S349nNA8L5+_1hrbWayqp8GfTYypWy_SP57c_Xxams=csg@mail.gmail.com> <51a066b3-4b4c-d573-ffbe-d6b44a4f193f@gont.com.ar> <a411a1b0-c521-c456-3d44-d99a1cc0975b@gmail.com> <CWXP265MB5153E4687BE45480DBC5A531C2439@CWXP265MB5153.GBRP265.PROD.OUTLOOK.COM> <27d28224-0cb0-eec2-8d54-f0d175596c85@gmail.com> <f5758380-9967-b67b-744d-dc36b7b599ab@si6networks.com> <4FCF75B585A1D068+7D9B99BB-B24B-4FE8-A3FD-54877C7C1131@cfiec.net> <375ea678-b05f-7bb6-5ae2-43c54cd271f4@si6networks.com> <CALx6S34u5=2UxEz3zeApv+_-W=PTj0PzMRHS1UC=zRchqVCDyQ@mail.gmail.com> <882610dc-cf8f-e08d-8d9e-0e786097f520@si6networks.com>
In-Reply-To: <882610dc-cf8f-e08d-8d9e-0e786097f520@si6networks.com>
From: Tom Herbert <tom@herbertland.com>
Date: Fri, 26 May 2023 14:37:06 -0700
Message-ID: <CALx6S34AnMaVyEVQxaO0b1JGbQetQvDC+xDHk6aH5vbXM-KT7A@mail.gmail.com>
To: Fernando Gont <fgont@si6networks.com>
Cc: "Haisheng Yu (Johnson)" <hsyu@cfiec.net>, "v6ops@ietf.org" <v6ops@ietf.org>, "ipv6@ietf.org" <ipv6@ietf.org>, "andrew.campling@419.consulting" <andrew.campling@419.consulting>, "opsec@ietf.org" <opsec@ietf.org>, "fernando@gont.com.ar" <fernando@gont.com.ar>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/N4VQK80ukYK_Q3CoIsXZmwXd9GY>
Subject: Re: [v6ops] [IPv6] [OPSEC] Why folks are blocking IPv 6 extension headers? (Episode 1000 and counting) (Linux DoS)
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 May 2023 21:37:23 -0000

On Fri, May 26, 2023 at 1:44 PM Fernando Gont <fgont@si6networks.com> wrote:
>
>
>
> On 26/5/23 18:01, Tom Herbert wrote:
> > On Fri, May 26, 2023 at 8:12 AM Fernando Gont <fgont@si6networks.com> wrote:
> [...]
> >>
> >> That said, I'm not that fine if invited to a party where, if anything, I
> >> will only pay the bills. So, I block everything that I don't use. e.g.,
> >> I have no use for EHs in any of my servers, except the pentesting boxes
> >> that I use to send weird packets to others.
> >
> > Fernando,
> >
> > If you're making that decision as the operator of a public network
> > then you are not making that decision for yourself, but you're making
>
> RFC9098.
>
> > a "big brother" decision for others and preventing permissionless
> > innovation as Brian stated nicely. I don't believe it could be claimed
> > that this is for "the good of the Internet".
>
> Companies are run to make money, not for the good of the Internet.

And IETF exists for the good of the Internet and the world's
population, not so your company can make money!

>
> And if your clients get downtime as a result of you keeping things wide
> open "for the good Internet", you'll likely have an interesting
> (unpleasant) conversation with your upstream management.
>
> Thanks,
> --
> Fernando Gont
> SI6 Networks
> e-mail: fgont@si6networks.com
> PGP Fingerprint: F242 FF0E A804 AF81 EB10 2F07 7CA1 321D 663B B494