[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Proposal: enable stateless persistant network interface names



On Wed, 13 May 2015 17:16:07 +0200, Vincent Lefevre
<vincent@vinc17.net> wrote:
>On 2015-05-12 22:31:43 +0200, Marc Haber wrote:
>> On Tue, 12 May 2015 17:08:33 +0200, Vincent Lefevre
>> <vincent@vinc17.net> wrote:
>> >On 2015-05-11 18:04:14 +0200, Marc Haber wrote:
>> >> In IPv6, routers advertise prefixes. If a new prefix comes, end
>> >> systems configured for SLAAC will allocate an IP address in this
>> >> prefix and begin to use it.
>> >
>> >On this subject, end systems under Debian are configured for SLAAC
>> >by default. :-(
>> 
>> I consider that a feature.
>
>Well, having some of the network traffic (more precisely, connections
>to machines that have an IPv6 address) re-routed to some unknown
>machine on the local network is not a nice feature.

Same can be accomplished with arp spoofing or by spoofing ND.
Disabling SLAAC does not improve security. otoh, it is very convenient
to have new systems reachable immediately.

Greetings
Marc
-- 
-------------------------------------- !! No courtesy copies, please !! -----
Marc Haber         |   " Questions are the         | Mailadresse im Header
Mannheim, Germany  |     Beginning of Wisdom "     | http://www.zugschlus.de/
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 621 72739834


Reply to: