Re: Allegations regarding OpenBSD IPSEC

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Otto Moerbeek
Date: Friday, December 24, 2010 - 1:09 pm

On Fri, Dec 24, 2010 at 07:53:52PM +0000, martin tarb wrote:


Huh, I quote:

"So a subverted developer would probably need to work on the network stack.
I can think of a few obvious ways that they could leak plaintext or key
material:"

and then Damien gives a few examples of how that could be accomplished.


What you describe above is one of the ways Damien mentions (as I read
it): "If I was doing it, I'd try to make the reuse happen on something
like ICMP errors, so I could send error-inducing probe packets at
times I thought were interesting "

Note the reuse of mbus will have the effect of sending key material to
the outside.

Please elaborate in what respect you suggestion is different.

	-Otto
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Allegations regarding OpenBSD IPSEC, Theo de Raadt, (Tue Dec 21, 11:29 am)
Re: Allegations regarding OpenBSD IPSEC, Kurt Knochner, (Tue Dec 21, 11:57 am)
Re: Allegations regarding OpenBSD IPSEC, martin tarb, (Fri Dec 24, 12:27 pm)
Re: Allegations regarding OpenBSD IPSEC, Otto Moerbeek, (Fri Dec 24, 12:38 pm)
Re: Allegations regarding OpenBSD IPSEC, martin tarb, (Fri Dec 24, 12:53 pm)
Re: Allegations regarding OpenBSD IPSEC, Otto Moerbeek, (Fri Dec 24, 1:09 pm)
Re: Allegations regarding OpenBSD IPSEC, martin tarb, (Fri Dec 24, 1:56 pm)
Re: Allegations regarding OpenBSD IPSEC, Janne Johansson, (Thu Dec 30, 1:38 am)
Re: Allegations regarding OpenBSD IPSEC, Ryan McBride, (Thu Dec 30, 1:56 am)
Re: Allegations regarding OpenBSD IPSEC, Kjell Wooding, (Thu Dec 30, 8:41 pm)
Re: Allegations regarding OpenBSD IPSEC, Otto Moerbeek, (Thu Dec 30, 11:57 pm)
Re: Allegations regarding OpenBSD IPSEC, Ray Percival, (Fri Dec 31, 10:16 am)