RE: RE: Comments on draft-adrangi-eap-network-discovery-07.txt
From: Glen Zorn (gwz) (gwzcisco.com)
Date: Fri, 11 Feb 2005 21:25:30 -0500 (EST)
Glen Zorn (gwz) <> supposedly scribbled:

...

>> 
>> In security section, we mention possible attack scenarios and
some
>> methods to prevent them.  Did we miss any?  What is the attack
>> scenario that you have in mind?

Sorry, I missed this one.  It seems that it enables attacks against
the greater network; it's not an attack against your protocol, per
se, but it seems that your protocol is giving away (by design) a lot
of information about network topology and even contracts to anybody
who happens along.  That's almost never a good idea.  It would be
far less revealing if the EAP peer were to send a list of realms it
was willing to use.

Hope this helps,

~gwz

Why is it that most of the world's problems can't be solved by
simply
  listening to John Coltrane? -- Henry Gabriel

Results generated by Tiger Technologies using MHonArc.