Vulnerability Development mailing list archives

Re: IPSec research


From: dugsong () MONKEY ORG (Dug Song)
Date: Sat, 25 Mar 2000 00:29:22 -0500


On Fri, 24 Mar 2000, Bep Verberk wrote:

Surely, there must be some inherent flaws ? What about the need for a
trusted key exchange system ? Is that vulnerable ?

IPsec is yet another standard designed by committee. it doesn't have
egregiously bad holes (thankfully, steve bellovin caught most of those),
but there are significant problems beyond its over-engineering and general
cruftiness.

see Bruce Schneier's excellent analysis of IPsec (tunnel vs. transport
mode, AH and ESP modes, etc.):

        http://www.counterpane.com/ipsec.html

and Bill Simpson's dire assessment of IKE (there's a good reason OpenBSD
offers Photuris as an alternative):

        http://www.usenix.org/publications/login/1999-12/features/harmful.html

-d.

---
http://www.monkey.org/~dugsong/



Current thread: