1 Apr 09:01
RE: Time shifitng/future redirection attacks
Kanchei Loa <loa <at> ieee.org>
2004-04-01 07:01:59 GMT
2004-04-01 07:01:59 GMT
marcelo bagnulo wrote: > I don't think that the decision is obvious but I think it is very > importatn > ti understand the additional vulnerabilities that we are > introducing. It may > be acceptable to introduce them, though. > I would like to point out that vulnerability is not always a bad thing as portrayed so far. In many situation, it become a feature for the application. For example, MiTM vulnerability has been the basis for NAT, firewall, load balancing proxy server (traffic director), TCP proxy for wireless subnet and many other so-called value-added network services. They are very important network components that support the exponential growth of Internet. IMHO I suggest the architecture document should provide a balance view on both security threats and value-added network services. In addition to the list of security threats, we should also compile a list of value-added network services. All proposals should be compared by not only the security threats being eliminated or introduced but also the value-added service being shutdown, added or refined. They are equally important issues for deployment and operation. For example, time shifting/future redirection attacks is a security threat for "drive-by coffeshop" but it provides a very nice feature for the "traffic director" whose job is to balance the load of the transport traffic among a groups of servers. Based on the vulnerability of time(Continue reading)
RSS Feed