Secdir early review of draft-ietf-rtgwg-srv6-egress-protection-16

2024-11-02 Thread Phillip Hallam-Baker via Datatracker
Reviewer: Phillip Hallam-Baker
Review result: Has Issues

I have reviewed this document and in general, it seems ready. While it does
raise serious security concerns, it is not clear that these are new to this
proposal or that this proposal gives more leverage to an attacker.

Specifically, the draft stipulates that 'the area is in a single administrative
domain' the security considerations describes one set of attacks arising from
customers served by the domain. However, this set of attacks may be broader
than described. Consider for instance the case where there are two domains A
and B that provide transit for ISP C. An attacker that wants to ensure C is
serviced exclusively by B might perform a denial of service attack on A so as
to increase the cost of that route so as to achieve that goal.

A real world attack that has been seen in the past is country X preparing for
an invasion of country Y, performing BGP level attacks to effectively reroute
Internet traffic within Y so that the government Web sites were serviced by
fake sites set up by X. These sites containing messages of the form 'don't
worry about the military exercises'.



___
rtgwg mailing list -- rtgwg@ietf.org
To unsubscribe send an email to rtgwg-le...@ietf.org


Re: WG adoption for draft-acee-rtgwg-vrrp-rfc8347bis (10/9/24-10/25/24)

2024-11-02 Thread Yingzhen Qu
Hi all,

The WG adoption is completed and the document is adopted.  Please republish
the document as draft-ietf-rtgwg-isis-vrrp-rfc8347bis-00 when the
datatracker reopens.

While there wasn't as much support as we would have liked maybe because
it was close to the IETF meeting, there were no objections. The chairs
believe this bis version is very much needed and thank the authors for
working on it.

Thanks,
Yingzhen

On Sat, Oct 12, 2024 at 8:50 AM Acee Lindem  wrote:

> Now all 5 co-authors have responded to the IPR poll.
>
> Thanks,
> Acee
>
> On Oct 12, 2024, at 10:02, Ravi Parikh  wrote:
>
> I am not aware of any IPR that applies to the draft. I support WG
> adoption.
>
> Thank you,
> Ravi Parikh.
>
> On Oct 12, 2024, at 5:06 AM, Xufeng Liu  wrote:
>
> I am not aware of any IPR that applies to the draft.
>
> I support WG adoption.
>
>
>
___
rtgwg mailing list -- rtgwg@ietf.org
To unsubscribe send an email to rtgwg-le...@ietf.org