From: "Michael T. Babcock" <mbabcock@fibrespeed.net>
To: lartc@vger.kernel.org
Subject: Re: [LARTC] Re: [release] ipsysctl tutorial 1.0.1
Date: Wed, 23 Oct 2002 18:59:44 +0000 [thread overview]
Message-ID: <marc-lartc-103539968803723@msgid-missing> (raw)
In-Reply-To: <marc-lartc-103539326825533@msgid-missing>
Oskar Andreasson wrote:
>>>may be of interest to some people on the netdev mailinglist as well.
>>>Just to inform people who may be interested, the ipsysctl tutorial has
>>>been released in a new version at http://ipsysctl-tutorial.frozentux.net.
>>>
>>>
I'd like to ask for some clarifications, if not quoting, in the tutorial
on page x321.html (not sure of section numbers) re: syn cookies.
Dan Bernstein (everyone's favorite mathematician :-) ) makes it very
clear on http://cr.yp.to/syncookies.html that your warnings are
primarily FUD. For the sake of quoting:
A few people (notably Alexey Kuznetsov, Wichert Akkerman, and Perry
Metzger) have been spreading misinformation about SYN cookies. Here are
some of their bogus claims:
* SYN cookies ``present serious violation of TCP protocol.''
Reality: SYN cookies are fully compliant with the TCP protocol.
Every packet sent by a SYN-cookie server is something that could
also have been sent by a non-SYN-cookie server.
* SYN cookies ``do not allow to use TCP extensions'' such as large
windows. Reality: SYN cookies don't hurt TCP extensions. A
connection saved by SYN cookies can't use large windows; but the
same is true without SYN cookies, because the connection would
have been destroyed.
* SYN cookies cause ``massive hanging connections.'' Reality: With
or without SYN cookies, connections occasionally hang because a
computer or network is overloaded. Applications deal with this by
simply dropping idle connections.
* SYN cookies cause ``serious degradation of service.'' Reality: SYN
cookies /improve/ service. They do take a small amount of CPU time
to compute, but that CPU time has to be spent anyway for
hard-to-predict sequence numbers; see RFC 1948.
* SYN cookies cause ``magic resets.'' Reality: SYN cookies never
cause resets.
These people also have the annoying habit of crediting their bogus
claims to other people, such as me. I don't know whether to attribute
this to malice or stupidity; either way, I would like the record to be
set straight.
I invited Kuznetsov to either retract or defend his claims. He refused
to do so. I'm sure he's aware by now that his claims are false, and that
any attempted defense will be promptly ripped to shreds; but he's still
not admitting his errors. It's unfortunate that he doesn't have more
respect for the truth.
I also invited Akkerman to either retract or defend his claims. He did
not respond.
--
Michael T. Babcock
C.T.O., FibreSpeed Ltd.
http://www.fibrespeed.net/~mbabcock
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/
next prev parent reply other threads:[~2002-10-23 18:59 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-10-23 17:13 [LARTC] Re: [release] ipsysctl tutorial 1.0.1 bert hubert
2002-10-23 18:39 ` Oskar Andreasson
2002-10-23 18:59 ` Michael T. Babcock [this message]
2002-10-24 17:56 ` Oskar Andreasson
2002-10-24 23:33 ` Michael T. Babcock
2002-10-28 19:55 ` Don Cohen
2002-10-28 20:16 ` Michael T. Babcock
2002-10-28 20:26 ` bert hubert
2002-10-28 20:31 ` Michael T. Babcock
2002-10-28 21:27 ` Oskar Andreasson
2002-10-29 14:32 ` Michael T. Babcock
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=marc-lartc-103539968803723@msgid-missing \
--to=mbabcock@fibrespeed.net \
--cc=lartc@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.