
Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [tlug] VPN
>>>>> "Tod" == Tod McQuillin <devin@example.com> writes:
Tod> Chris omits to mention why SSL and other TCP/IP based
Tod> solutions (like ppp over SSH etc) are a bad idea:
Tod> http://sites.inka.de/sites/bigred/devel/tcp-tcp.html
Eh, I think Chris's "crack" meant "crack", not "DoS".
However, that URL is definitely very relevant, and one should note
that even IPsec is not invulnerable to such problems. At least in the
sense that some (perhaps poorly designed) protocols like the Coda
distributed file system can get quite confused by the combination of
loss of access to the real headers and carrier-level fragmentation.
--
Institute of Policy and Planning Sciences http://turnbull.sk.tsukuba.ac.jp
University of Tsukuba Tennodai 1-1-1 Tsukuba 305-8573 JAPAN
Ask not how you can "do" free software business;
ask what your business can "do for" free software.
Home |
Main Index |
Thread Index