search for: 04ca6973f7c1a0d

Displaying 20 results from an estimated 22 matches for "04ca6973f7c1a0d".

2015 Jan 28
3
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...9;s certainly harder to get hold of entropy > guest-side. It is not only about entropy but about uniqueness. Also fragmentation ids should not be discoverable, so there are several aspects: I see fragmentation id generation still as security critical: When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP identifiers less predictable") I could patch my kernels and use the patch regardless of the machine being virtualized or not. It was not dependent on the hypervisor. I think that is the same reasoning why we don't support TOE. If we use one generator in the hypervisor i...
2015 Jan 28
3
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...9;s certainly harder to get hold of entropy > guest-side. It is not only about entropy but about uniqueness. Also fragmentation ids should not be discoverable, so there are several aspects: I see fragmentation id generation still as security critical: When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP identifiers less predictable") I could patch my kernels and use the patch regardless of the machine being virtualized or not. It was not dependent on the hypervisor. I think that is the same reasoning why we don't support TOE. If we use one generator in the hypervisor i...
2015 Jan 28
7
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...; ids should not be discoverable, > > I belive "predictable" is the language used by the IETF draft. > > > so there are several aspects: > > > > I see fragmentation id generation still as security critical: > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > identifiers less predictable") I could patch my kernels and use the > > patch regardless of the machine being virtualized or not. It was not > > dependent on the hypervisor. > > And now it's even easier - just patch the hypervisor, and all VM...
2015 Jan 28
7
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...; ids should not be discoverable, > > I belive "predictable" is the language used by the IETF draft. > > > so there are several aspects: > > > > I see fragmentation id generation still as security critical: > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > identifiers less predictable") I could patch my kernels and use the > > patch regardless of the machine being virtualized or not. It was not > > dependent on the hypervisor. > > And now it's even easier - just patch the hypervisor, and all VM...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...;> I belive "predictable" is the language used by the IETF draft. > >> > >>> so there are several aspects: > >>> > >>> I see fragmentation id generation still as security critical: > >>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > >>> identifiers less predictable") I could patch my kernels and use the > >>> patch regardless of the machine being virtualized or not. It was not > >>> dependent on the hypervisor. > >> > >> And now it's even easie...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...;> I belive "predictable" is the language used by the IETF draft. > >> > >>> so there are several aspects: > >>> > >>> I see fragmentation id generation still as security critical: > >>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > >>> identifiers less predictable") I could patch my kernels and use the > >>> patch regardless of the machine being virtualized or not. It was not > >>> dependent on the hypervisor. > >> > >> And now it's even easie...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...ive "predictable" is the language used by the IETF draft. > > > > > > > so there are several aspects: > > > > > > > > I see fragmentation id generation still as security critical: > > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > > identifiers less predictable") I could patch my kernels and use the > > > > patch regardless of the machine being virtualized or not. It was not > > > > dependent on the hypervisor. > > > > > > And now it's e...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...ive "predictable" is the language used by the IETF draft. > > > > > > > so there are several aspects: > > > > > > > > I see fragmentation id generation still as security critical: > > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > > identifiers less predictable") I could patch my kernels and use the > > > > patch regardless of the machine being virtualized or not. It was not > > > > dependent on the hypervisor. > > > > > > And now it's e...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...uniqueness. Also fragmentation > ids should not be discoverable, I belive "predictable" is the language used by the IETF draft. > so there are several aspects: > > I see fragmentation id generation still as security critical: > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > identifiers less predictable") I could patch my kernels and use the > patch regardless of the machine being virtualized or not. It was not > dependent on the hypervisor. And now it's even easier - just patch the hypervisor, and all VMs automatically benefit....
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...uniqueness. Also fragmentation > ids should not be discoverable, I belive "predictable" is the language used by the IETF draft. > so there are several aspects: > > I see fragmentation id generation still as security critical: > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > identifiers less predictable") I could patch my kernels and use the > patch regardless of the machine being virtualized or not. It was not > dependent on the hypervisor. And now it's even easier - just patch the hypervisor, and all VMs automatically benefit....
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...iscoverable, >> >> I belive "predictable" is the language used by the IETF draft. >> >>> so there are several aspects: >>> >>> I see fragmentation id generation still as security critical: >>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP >>> identifiers less predictable") I could patch my kernels and use the >>> patch regardless of the machine being virtualized or not. It was not >>> dependent on the hypervisor. >> >> And now it's even easier - just patch the hyperv...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...iscoverable, >> >> I belive "predictable" is the language used by the IETF draft. >> >>> so there are several aspects: >>> >>> I see fragmentation id generation still as security critical: >>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP >>> identifiers less predictable") I could patch my kernels and use the >>> patch regardless of the machine being virtualized or not. It was not >>> dependent on the hypervisor. >> >> And now it's even easier - just patch the hyperv...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; > > > I belive "predictable" is the language used by the IETF draft. > > > > > so there are several aspects: > > > > > > I see fragmentation id generation still as security critical: > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > identifiers less predictable") I could patch my kernels and use the > > > patch regardless of the machine being virtualized or not. It was not > > > dependent on the hypervisor. > > > > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; > > > I belive "predictable" is the language used by the IETF draft. > > > > > so there are several aspects: > > > > > > I see fragmentation id generation still as security critical: > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > identifiers less predictable") I could patch my kernels and use the > > > patch regardless of the machine being virtualized or not. It was not > > > dependent on the hypervisor. > > > > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; > > > I belive "predictable" is the language used by the IETF draft. > > > > > so there are several aspects: > > > > > > I see fragmentation id generation still as security critical: > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > identifiers less predictable") I could patch my kernels and use the > > > patch regardless of the machine being virtualized or not. It was not > > > dependent on the hypervisor. > > > > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; > > > I belive "predictable" is the language used by the IETF draft. > > > > > so there are several aspects: > > > > > > I see fragmentation id generation still as security critical: > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > identifiers less predictable") I could patch my kernels and use the > > > patch regardless of the machine being virtualized or not. It was not > > > dependent on the hypervisor. > > > > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
..."predictable" is the language used by the IETF draft. >>>> >>>>> so there are several aspects: >>>>> >>>>> I see fragmentation id generation still as security critical: >>>>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP >>>>> identifiers less predictable") I could patch my kernels and use the >>>>> patch regardless of the machine being virtualized or not. It was not >>>>> dependent on the hypervisor. >>>> >>>> And now it...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
..."predictable" is the language used by the IETF draft. >>>> >>>>> so there are several aspects: >>>>> >>>>> I see fragmentation id generation still as security critical: >>>>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP >>>>> identifiers less predictable") I could patch my kernels and use the >>>>> patch regardless of the machine being virtualized or not. It was not >>>>> dependent on the hypervisor. >>>> >>>> And now it...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...t; is the language used by the IETF draft. > > > > > > > > > so there are several aspects: > > > > > > > > > > I see fragmentation id generation still as security critical: > > > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > > > identifiers less predictable") I could patch my kernels and use the > > > > > patch regardless of the machine being virtualized or not. It was not > > > > > dependent on the hypervisor. > > > > > > &gt...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...t; is the language used by the IETF draft. > > > > > > > > > so there are several aspects: > > > > > > > > > > I see fragmentation id generation still as security critical: > > > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP > > > > > identifiers less predictable") I could patch my kernels and use the > > > > > patch regardless of the machine being virtualized or not. It was not > > > > > dependent on the hypervisor. > > > > > > &gt...