[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: I-D.ietf-v6ops-cpe-simple-security-09



On 3/21/10 7:00 AM, james woodyatt wrote:
On Mar 20, 2010, at 18:00, Mark Smith wrote:
One thing that does seem to be missing from the draft is a specific list of threats it is attempting to mitigate i.e. a threat model.
RFC 4864 doesn't offer one, and its authors haven't offered much in the way of specifics to the discussion here or on the design team list.  Perhaps, you'd like to offer a contribution?

The Overview contains my best attempt at explaining what considerations I think are really in play behind the CPE Simple Security recommendation.  Here's what I think is the most relevant excerpt:

The stateful packet filtering behavior of NAT set user expectations that persist today with residential IPv6 service.  "Local Network Protection for IPv6" [RFC4864] recommends applying stateful packet filtering at residential IPv6 gateways that conforms to the user expectations already in place.
In other words, we recommend filtering at the middlebox-- making IPv6 routers do filtering like IPv4/NAT gateways do-- because "defense in depth" is a virtue in and of itself, and that Internet users have come to expect it.  Apparently, there's a consensus in IETF that this is enough reason to do it, and I strongly suspect that an explicit threat model might be inviting more controversy than anyone wants to endure.
So, you are saying there is IETF consensus on a security solution for IPv6 based largely on the status quo of IPv4, but no consensus on what security problem either are actually solving. If we are shooting for status quo and similar user experience, we should go ahead and include NAT. At least then the user gets stable independent addressing, regardless of what the ISP offers.

Imagine Los Angeles manages to get everyone to move to electric cars, but the local populace decides that they liked the smog that blocked the sun, the daily pollution indicators, etc. and decides to pump smoke into the atmosphere to ensure that the user expectation of the inhabitants remains unchanged.

- Mark

--
james woodyatt<jhw@apple.com>
member of technical staff, communications engineering