|
|
Subscribe / Log in / New account

So you think you understand IP fragmentation?

So you think you understand IP fragmentation?

Posted Feb 8, 2024 11:33 UTC (Thu) by Wol (subscriber, #4433)
In reply to: So you think you understand IP fragmentation? by paulj
Parent article: So you think you understand IP fragmentation?

When the CRA comes into effect, all we need is a serious security bug (heartbleed?) caused by ICMP filtering, and all these router vendors will be scrambling to fix their routers to work properly :-)

Cheers,
Wol


to post comments

So you think you understand IP fragmentation?

Posted Feb 23, 2024 15:48 UTC (Fri) by sammythesnake (guest, #17693) [Link]

Colour me sceptical on that idea. I imagine that in such a case there would be some vigorously partisan "discussions" of exactly where responsibility lies - is the router responsible for how the source/destination behaves when packets go missing?

I think there's a good argument that occasional missing packets is a normally expected behaviour of "the internet" - a whole lot of the specs for things like TCP/IP exist specifically because of that fact. When it happens unnecessarily, that's certainly a *performance* issue, but not a *security* issue in some random part of the internet, rather in any end-point that reacts by leaking information or whatever.

Any endpoint that can't stay as safe as a "connection failed" error really shouldn't be dealing with anything security related...

If an intermediary on the path *rewrites* stuff, that's a much harder thing to justify by this kind of argument, but even then I think the more reasonable next step is ensuring integrity/privacy via end-to-end encryption because the internet is a hostile environment full of baddies of all kinds, not just crappy middleboxen (e.g. a whole alphabet soup of state agencies who absolutely do not share my priorities with regard to my internet traffic(!))


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds