Re: [v6ops] draft-ietf-v6ops-balanced-ipv6-security WGLC

joel jaeggli <joelja@bogus.com> Thu, 14 November 2013 19:22 UTC

Return-Path: <joelja@bogus.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3400A11E8104 for <v6ops@ietfa.amsl.com>; Thu, 14 Nov 2013 11:22:14 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -101.999
X-Spam-Level:
X-Spam-Status: No, score=-101.999 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, J_CHICKENPOX_13=0.6, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8fpH5rh-j6Lo for <v6ops@ietfa.amsl.com>; Thu, 14 Nov 2013 11:22:13 -0800 (PST)
Received: from nagasaki.bogus.com (nagasaki.bogus.com [IPv6:2001:418:1::81]) by ietfa.amsl.com (Postfix) with ESMTP id C24CF11E80FA for <v6ops@ietf.org>; Thu, 14 Nov 2013 11:22:13 -0800 (PST)
Received: from 00698a-hsutim.corp.zynga.com ([199.48.105.4]) (authenticated bits=0) by nagasaki.bogus.com (8.14.4/8.14.4) with ESMTP id rAEJMBqU050426 (version=TLSv1/SSLv3 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NOT); Thu, 14 Nov 2013 19:22:11 GMT (envelope-from joelja@bogus.com)
Message-ID: <528522DD.5010600@bogus.com>
Date: Thu, 14 Nov 2013 11:22:05 -0800
From: joel jaeggli <joelja@bogus.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Thunderbird/25.0
MIME-Version: 1.0
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, Mikael Abrahamsson <swmike@swm.pp.se>
References: <201311101900.rAAJ0AR6025350@irp-view13.cisco.com> <CAB0C4xOfz_JAjEEJZ-Zz7MBEyZhVzrAE+8Ghf1ggC3+9pyHmNg@mail.gmail.com> <989B8ED6-273E-45D4-BFD8-66A1793A1C9F@cisco.com> <alpine.DEB.2.02.1311130329180.26054@uplift.swm.pp.se> <CAB0C4xOd-ryBXe4O3XoLTLDw-XuOV==X0nkRg5y3aPXCtf+Gow@mail.gmail.com> <alpine.DEB.2.02.1311140639140.5805@uplift.swm.pp.se> <5FC5FC3F-B933-4ACE-A7A9-00A1E275B4EF@cisco.com> <alpine.DEB.2.02.1311140745080.5805@uplift.swm.pp.se> <528520ED.8060902@gmail.com>
In-Reply-To: <528520ED.8060902@gmail.com>
X-Enigmail-Version: 1.6
Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="cqQJjOkOi5KcssVQgXw0cuXFbvVN9dkLg"
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.2.7 (nagasaki.bogus.com [147.28.0.81]); Thu, 14 Nov 2013 19:22:11 +0000 (UTC)
Cc: IPv6 Operations <v6ops@ietf.org>
Subject: Re: [v6ops] draft-ietf-v6ops-balanced-ipv6-security WGLC
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 14 Nov 2013 19:22:14 -0000

On 11/14/13, 11:13 AM, Brian E Carpenter wrote:
> On 14/11/2013 19:56, Mikael Abrahamsson wrote:
> ...
>> Most of the devices today can handle themselves having unfiltered access
>> to the Internet. Phones and computers are regularily exposed to the
>> Internet and have sane defaults to handle this. 
> 
> That's a vital point. Mobile devices, including laptops, are potentially
> exposed to raw Internet, so relying on a separate firewall is totally
> unsafe. That's not to say that firewalls are pointless - it's helpful if
> unwanted traffic is dropped at the perimeter - but if your device isn't
> intrinsically protected, all hope is lost as soon as you step outside
> the building. In these days of BYOD, unprotected devices will end up
> infected and will later infect the corporate network, so even screwed-down
> desktop devices need intrinsic protection.

It is reasonable to suppose that most devices should not assume that a
home network is anymore trustworthly or less potentially hostile than
any other... Hard crunchy exterior and soft gooey center is best
reserved for candy-bars.

> That said, the *informational* draft in question is useful as an example
> of a possible deployment scenario.
> 
>     Brian
> _______________________________________________
> v6ops mailing list
> v6ops@ietf.org
> https://www.ietf.org/mailman/listinfo/v6ops
>