All of lore.kernel.org
 help / color / mirror / Atom feed
From: Alexander Morlang <alx@dd19.de>
To: The list for a Better Approach To Mobile Ad-hoc Networking
	<b.a.t.m.a.n@open-mesh.net>
Subject: Re: [B.A.T.M.A.N.] securing batman gateway
Date: Thu, 28 Jun 2007 13:34:55 +0200	[thread overview]
Message-ID: <46839CDF.30106@dd19.de> (raw)
In-Reply-To: <200706271208.19749.lindner_marek@yahoo.de>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



Marek Lindner schrieb:
> Hi,
> 
> 
>> Batman has a tunnel with gateway but is it possible to secure it? In first
>> step only clients with proper credentials can start tunnel and in second
>> step tunnel is crypted.
> 
> I agree that this would be a good idea. Using the batman tunnels would be much 
> easier to set up than IPSec as everything is integrated. Besides that a 
> lightweight encryption could be implemented which even runs on weaker 
> machines.

What is lightweight encryption? Does lightweight means insecure? Is it
easier, because you are not familiar with IPSEC?

building unsecure crypto ist worse then having no crypto, it would be a
"sicherheitsimulation". building strong crypto is not easy, so many
failed to develop and implement it with more and better
cryptospecialists the the batman team has.

> 
> That feature is planned and a concept already exists. Nevertheless, the batman 
> developer team has a divided opinion about this idea. Some of us (inlucing 
> me) think that it a good opportunity to help spreading internet gateways 
> throughout a city wide mesh. The others fear that this could be the beginning 
> of the end of free mesh networks if we implement such control mechanisms.
> What do you think ? Why do you want this feature ?

Some batman developer once told me, that implementing/supporting service
discovery inside batman is a bad idea, as they want to have batman as
slim as possible.
how does integrating cryptotunnels in a routingprotocol does get conform
to that?

> 
> Btw: Does your vis server compile now ?
> 
> Regards,
> Marek


Greets, Alex
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGg5zfhx2RbV7T5aERAnhIAJ9SuEqQMAi6BjMwTZ2/KQ33ChpQfQCggVei
dI8wMB7ezWgPIS4Ko7kiMJo=
=bY0R
-----END PGP SIGNATURE-----

  reply	other threads:[~2007-06-28 11:34 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-06-26 15:23 [B.A.T.M.A.N.] securing batman gateway Stefano Scipioni
2007-06-26 22:31 ` Alexander Morlang
2007-06-27 10:08 ` Marek Lindner
2007-06-28 11:34   ` Alexander Morlang [this message]
2007-06-28 13:46     ` Marek Lindner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=46839CDF.30106@dd19.de \
    --to=alx@dd19.de \
    --cc=b.a.t.m.a.n@open-mesh.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.