From: Jesse Brandeburg <jesse.brandeburg@intel.com>
To: David Miller <davem@redhat.com>
Cc: <therbert@google.com>, <David.Laight@aculab.com>,
<netdev@vger.kernel.org>
Subject: Re: [PATCH 1/2] net: Toeplitz library functions
Date: Tue, 24 Sep 2013 11:48:53 -0700 [thread overview]
Message-ID: <20130924114853.00003935@unknown> (raw)
In-Reply-To: <20130924.140312.1944338200709799169.davem@redhat.com>
On Tue, 24 Sep 2013 14:03:12 -0400 David Miller <davem@redhat.com> wrote:
...
> >> For security reasons we absolutely cannot use it for that purpose,
> >> please stop claiming this.
> >>
> >> Any hash function which an attacker can reproduce is attackable.
> >
...
> > that should be addressed. It is possible to DoS attack through the
> > steering mechanism.
>
> All of them are using a fixed, defined, key.
We selected the fixed key on purpose. The existing mechanisms built
into the stack for preventing the impact of DOS attacks like NAPI
polling will prevent any actual damage even if someone sends lots of
packets on a single flow. If someone overflows a receive queue that
CPU runs until it can't keep up and then hardware drops further
packets. In this case even with a randomized seed key any single flow
can still be targeted at a queue, which is no different than a single
queue adapter.
I'm not convinced there is an actual impact in practice.
next prev parent reply other threads:[~2013-09-24 18:48 UTC|newest]
Thread overview: 50+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-09-23 22:41 [PATCH 1/2] net: Toeplitz library functions Tom Herbert
2013-09-24 0:03 ` Eric Dumazet
2013-09-24 1:39 ` David Miller
2013-09-24 2:30 ` Hannes Frederic Sowa
2013-09-24 3:35 ` Hannes Frederic Sowa
2013-09-24 5:38 ` Eric Dumazet
2013-09-24 5:45 ` Hannes Frederic Sowa
2013-09-24 13:19 ` [PATCH] net: net_secret should not depend on TCP Eric Dumazet
2013-09-24 15:13 ` Hannes Frederic Sowa
2013-09-24 15:22 ` Eric Dumazet
2013-09-24 15:28 ` Hannes Frederic Sowa
2013-09-24 15:46 ` Eric Dumazet
2013-09-24 23:51 ` Hannes Frederic Sowa
2013-09-28 22:20 ` David Miller
2013-09-25 9:00 ` [PATCH RFC] random: introduce get_random_bytes_busy_wait_initialized Hannes Frederic Sowa
2013-09-25 12:06 ` Eric Dumazet
2013-09-25 13:35 ` Hannes Frederic Sowa
2013-10-02 15:10 ` Theodore Ts'o
2013-10-02 17:18 ` Hannes Frederic Sowa
2013-10-02 19:40 ` Theodore Ts'o
2013-09-24 16:01 ` [PATCH 1/2] net: Toeplitz library functions Hannes Frederic Sowa
2013-09-24 16:14 ` Eric Dumazet
2013-09-24 16:35 ` Tom Herbert
2013-09-24 16:46 ` Eric Dumazet
2013-09-24 17:02 ` Ben Hutchings
2013-09-24 17:03 ` Tom Herbert
2013-09-24 17:34 ` Eric Dumazet
2013-09-24 17:37 ` Rick Jones
2013-09-24 17:44 ` Eric Dumazet
2013-09-24 18:02 ` Tom Herbert
2013-09-24 18:48 ` David Miller
2013-09-24 19:42 ` Hannes Frederic Sowa
2013-09-24 8:32 ` David Laight
2013-09-24 12:24 ` Eric Dumazet
2013-09-24 15:22 ` Tom Herbert
2013-09-24 15:29 ` Eric Dumazet
2013-09-24 15:39 ` David Miller
2013-09-24 15:54 ` Tom Herbert
2013-09-24 16:00 ` Hannes Frederic Sowa
2013-09-24 16:10 ` Eric Dumazet
2013-09-24 18:03 ` David Miller
2013-09-24 18:06 ` Tom Herbert
2013-09-24 18:10 ` Ben Hutchings
2013-09-24 18:24 ` Tom Herbert
2013-09-24 19:14 ` Eric Dumazet
2013-09-24 18:49 ` David Miller
2013-09-24 18:48 ` Jesse Brandeburg [this message]
2013-09-24 19:04 ` Tom Herbert
2013-09-24 16:38 ` Ben Hutchings
2013-09-24 16:32 ` Ben Hutchings
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20130924114853.00003935@unknown \
--to=jesse.brandeburg@intel.com \
--cc=David.Laight@aculab.com \
--cc=davem@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=therbert@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).