Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] VPN



>>>>> "Tod" == Tod McQuillin <devin@example.com> writes:

    Tod> Chris omits to mention why SSL and other TCP/IP based
    Tod> solutions (like ppp over SSH etc) are a bad idea:

    Tod> http://sites.inka.de/sites/bigred/devel/tcp-tcp.html

Eh, I think Chris's "crack" meant "crack", not "DoS".

However, that URL is definitely very relevant, and one should note
that even IPsec is not invulnerable to such problems.  At least in the
sense that some (perhaps poorly designed) protocols like the Coda
distributed file system can get quite confused by the combination of
loss of access to the real headers and carrier-level fragmentation.


-- 
Institute of Policy and Planning Sciences     http://turnbull.sk.tsukuba.ac.jp
University of Tsukuba                    Tennodai 1-1-1 Tsukuba 305-8573 JAPAN
               Ask not how you can "do" free software business;
              ask what your business can "do for" free software.


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links