Re: enc0 patch for ipsec
- From: Max Laier <max@xxxxxxxxxxxxxx>
- Date: Fri, 16 Jun 2006 18:14:12 +0200
On Friday 16 June 2006 18:09, Scott Ullrich wrote:
On 6/16/06, Max Laier <max@xxxxxxxxxxxxxx> wrote:
The issue is, if an attacker manages to get root on your box they are
automatically able to read your IPSEC traffic ending at that box. If you
don't have enc(4) compiled in, that would be more difficult to do. Same
reason you don't want SADB_FLUSH on by default.
Okay, this makes sense. But couldn't you also argue that if someone
gets access to the machine they could also use tcpdump to do the same
thing technically on the internal interface? Just playing devils
advocate.. :)
Think tunnel2tunnel or an SA for a local connection, then. Given, if you are
root you *might* have other means to obtain that information, but that is why
we have a switch to turn off bpf, kmem or the like.
--
/"\ Best regards, | mlaier@xxxxxxxxxxx
\ / Max Laier | ICQ #67774661
X http://pf4freebsd.love2party.net/ | mlaier@EFnet
/ \ ASCII Ribbon Campaign | Against HTML Mail and News
Attachment:
pgp6Cq5001yHM.pgp
Description: PGP signature
- Follow-Ups:
- Re: enc0 patch for ipsec
- From: Scott Ullrich
- Re: enc0 patch for ipsec
- From: Andrew Thompson
- Re: enc0 patch for ipsec
- References:
- enc0 patch for ipsec
- From: Andrew Thompson
- Re: enc0 patch for ipsec
- From: Max Laier
- Re: enc0 patch for ipsec
- From: Scott Ullrich
- enc0 patch for ipsec
- Prev by Date: Re: enc0 patch for ipsec
- Next by Date: Re: enc0 patch for ipsec
- Previous by thread: Re: enc0 patch for ipsec
- Next by thread: Re: enc0 patch for ipsec
- Index(es):
Relevant Pages
- Re: enc0 patch for ipsec
... On Friday 16 June 2006 18:09, Scott Ullrich wrote: ... automatically able to
read your IPSEC traffic ending at that box. ... thing technically on the internal interface?
... Just playing devils ... (freebsd-net) - Re: enc0 patch for ipsec
... On 6/16/06, Max Laier wrote: ... automatically able to read your IPSEC traffic
ending at that box. ... thing technically on the internal interface? ... Just
playing devils ... (freebsd-net) - Re: enc0 patch for ipsec
... On 6/16/06, Max Laier wrote: ... automatically able to read your IPSEC traffic
ending at that box. ... thing technically on the internal interface? ... Just
playing devils ... (freebsd-arch)