netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* RFC:  p&p ipsec without authentication
@ 2002-12-15 20:34 Rik van Riel
  2002-12-15 21:59 ` Andrew McGregor
  0 siblings, 1 reply; 2+ messages in thread
From: Rik van Riel @ 2002-12-15 20:34 UTC (permalink / raw)
  To: netdev; +Cc: linux-kernel

Hi,

I've got a crazy idea.  I know it's not secure, but I think it'll
add some security against certain attacks, while being non-effective
against some others.

The idea I have is letting the ipsec layer do opportunistic encryption
even when there are no ipsec keys known for the destination address,
ie. negotiate a key when none is in the configuration or DNS.

I know this gives absolutely no protection against man-in-the-middle
attacks (except maybe being able to detect them), but it should prevent
passive sniffing of network traffic, as done by some governments.

If this "random" encryption could be turned on with one argument to
ip or ifconfig and millions of hosts would use it, sniffing internet
traffic might just become impractical (or too expensive) for large
organisations.   Furthermore, even if just 0.1% of the hosts were to
use ipsec authentication, the 3-letter agencies would be faced with
the additional challenge of identifying which connections could safely
be intercepted with man-in-the-middle attacks and which couldn't.

Not to mention the fact that the port number on many communications
would be invisible, vastly increasing the difficulty of doing any
kind of statistical analysis on the traffic that's traversing the
network.

Is this idea completely crazy or only slightly ?

regards,

Rik
-- 
Bravely reimplemented by the knights who say "NIH".
http://www.surriel.com/		http://guru.conectiva.com/
Current spamtrap:  <a href=mailto:"october@surriel.com">october@surriel.com</a>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2002-12-15 21:59 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-12-15 20:34 RFC: p&p ipsec without authentication Rik van Riel
2002-12-15 21:59 ` Andrew McGregor

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).