Re: CARP hash vuln

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Marco Pfatschbacher
Date: Tuesday, December 21, 2010 - 2:26 am

On Tue, Dec 21, 2010 at 09:34:01AM +0100, David Coppa wrote:

If you look at my commit message from 3 years ago,
you'll see that we are well aware of this:

 http://www.openbsd.org/cgi-bin/cvsweb/src/sys/netinet/ip_carp.c?f=h#rev1.152

If someone comes up with a replay protection that works without the help
of synchronized clocks, I'm happy to fix this.

OTOH, I'm still not convinced that it's worth the effort to fix a
L2-only attack. There's still enough other ways for a DoS on L2.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: CARP hash vuln, David Coppa, (Tue Dec 21, 1:34 am)
Re: CARP hash vuln, Marco Pfatschbacher, (Tue Dec 21, 2:26 am)