1 Nov 2002 06:05
RE: I-D ACTION:draft-kobayakawa-ipsec-ipv6-pnpipsec-reqts-00.txt
Jan Vilhuber <vilhuber <at> cisco.com>
2002-11-01 05:05:29 GMT
2002-11-01 05:05:29 GMT
Presumably only passive wiretapping kinds of attacks. <joking> Maybe we should standardize the april fools draft-rfc pre-shared key for IKE as the default password for plug-and-play ipsec? </joking> I'm not sure if this is a really good idea or a really bad one (as a professional paranoiac, I tend towards the later). Bad idea? False sense of security because now everyone thinks they are being protected by ipsec (and really aren't, at least not terribly much)? or Good idea? A quick way to roll standard IPsec out to the masses with a clean upgrade path: start deploying real pre-shared keys or certificates (or dnssec or whatever) and use the tasty goat key only if all else fails (still leaving the impression we're very secure when we're not?)? Hm... tasty goat, if I do say so myself ;) Can you make me one? jan On Thu, 31 Oct 2002 rcharlet <at> SonicWALL.com wrote: > Howdy, > > What threat would this succeed in averting?(Continue reading)
RSS Feed