On 10/24/07, Henning Brauer wrote:
I agree, the key is the reasonably configured part. Vlan hopping, STP
attacks, etc. and Cisco particularly. Even if Cisco is (now) one of
the few to not have sane defaults, they're common enough for it to be
a concern. And consider all the devices (even from good vendors) that
are behind on firmware (where the defaults weren't yet sane).
If this wasn't the case, Yersinia wouldn't be nearly as interesting as it is.
> this comparision is wrong on another basis: vlans are dead simple, just
Yeah, I was commenting mainly on the flawed "silver bullet" mentality
that some LAN admins have with the "if I have VLANs, my hosts are
automatically perfectly segmented" mindset rather than the
implementation/design itself. Sadly, the average LAN admin these days,
at least in the states, isn't smart enough to understand the nuances.
DS
| Andreas Gruenbacher | Re: [AppArmor 39/45] AppArmor: Profile loading and manipulation, pathname matching |
| Alan Cox | Re: [patch 7/8] fdmap v2 - implement sys_socket2 |
| Jens Axboe | Re: regression: CD burning (k3b) went broke |
| Paul E. McKenney | Re: [PATCH 0/24] make atomic_read() behave consistently across all architectures |
git: | |
| KOSAKI Motohiro | [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| David Miller | [GIT]: Networking |
| Alexey Dobriyan | [PATCH 09/33] netns ct: per-netns /proc/net/nf_conntrack, /proc/net/stat/nf_conntr... |
| Gerrit Renker | [PATCH 18/37] dccp: Support for Mandatory options |
