Winstar says there is no TCP/BGP vulnerability

Pekka Savola pekkas at netcore.fi
Wed Apr 21 11:23:38 UTC 2004


On Wed, 21 Apr 2004, E.B. Dreger wrote:
> DH> Date: Wed, 21 Apr 2004 02:01:56 -0700 (PDT)
> DH> From: Dan Hollis
> 
> DH> Wouldnt anti-spoofing filters largely eliminate the need for
> DH> all this panic about MD5?
> 
> But that doesn't push the short-term cost onto other networks.

Not sure what you're saying.  You don't need to deploy anti-spoofing 
filters everywhere.  It needs to be done by those parties which are 
the ones setting up MD5 passwords.  No more than that. (See my thread 
"Alternatives to MD5" for more.)

-- 
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings






More information about the NANOG mailing list