Displaying 20 results from an estimated 22 matches for "04ca6973f7c1a0d".
2015 Jan 28
3
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...9;s certainly harder to get hold of entropy
> guest-side.
It is not only about entropy but about uniqueness. Also fragmentation
ids should not be discoverable, so there are several aspects:
I see fragmentation id generation still as security critical:
When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
identifiers less predictable") I could patch my kernels and use the
patch regardless of the machine being virtualized or not. It was not
dependent on the hypervisor. I think that is the same reasoning why we
don't support TOE.
If we use one generator in the hypervisor i...
2015 Jan 28
3
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...9;s certainly harder to get hold of entropy
> guest-side.
It is not only about entropy but about uniqueness. Also fragmentation
ids should not be discoverable, so there are several aspects:
I see fragmentation id generation still as security critical:
When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
identifiers less predictable") I could patch my kernels and use the
patch regardless of the machine being virtualized or not. It was not
dependent on the hypervisor. I think that is the same reasoning why we
don't support TOE.
If we use one generator in the hypervisor i...
2015 Jan 28
7
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...; ids should not be discoverable,
>
> I belive "predictable" is the language used by the IETF draft.
>
> > so there are several aspects:
> >
> > I see fragmentation id generation still as security critical:
> > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > identifiers less predictable") I could patch my kernels and use the
> > patch regardless of the machine being virtualized or not. It was not
> > dependent on the hypervisor.
>
> And now it's even easier - just patch the hypervisor, and all VM...
2015 Jan 28
7
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...; ids should not be discoverable,
>
> I belive "predictable" is the language used by the IETF draft.
>
> > so there are several aspects:
> >
> > I see fragmentation id generation still as security critical:
> > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > identifiers less predictable") I could patch my kernels and use the
> > patch regardless of the machine being virtualized or not. It was not
> > dependent on the hypervisor.
>
> And now it's even easier - just patch the hypervisor, and all VM...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...;> I belive "predictable" is the language used by the IETF draft.
> >>
> >>> so there are several aspects:
> >>>
> >>> I see fragmentation id generation still as security critical:
> >>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> >>> identifiers less predictable") I could patch my kernels and use the
> >>> patch regardless of the machine being virtualized or not. It was not
> >>> dependent on the hypervisor.
> >>
> >> And now it's even easie...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...;> I belive "predictable" is the language used by the IETF draft.
> >>
> >>> so there are several aspects:
> >>>
> >>> I see fragmentation id generation still as security critical:
> >>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> >>> identifiers less predictable") I could patch my kernels and use the
> >>> patch regardless of the machine being virtualized or not. It was not
> >>> dependent on the hypervisor.
> >>
> >> And now it's even easie...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...ive "predictable" is the language used by the IETF draft.
> > >
> > > > so there are several aspects:
> > > >
> > > > I see fragmentation id generation still as security critical:
> > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > > identifiers less predictable") I could patch my kernels and use the
> > > > patch regardless of the machine being virtualized or not. It was not
> > > > dependent on the hypervisor.
> > >
> > > And now it's e...
2015 Jan 28
2
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...ive "predictable" is the language used by the IETF draft.
> > >
> > > > so there are several aspects:
> > > >
> > > > I see fragmentation id generation still as security critical:
> > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > > identifiers less predictable") I could patch my kernels and use the
> > > > patch regardless of the machine being virtualized or not. It was not
> > > > dependent on the hypervisor.
> > >
> > > And now it's e...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...uniqueness. Also fragmentation
> ids should not be discoverable,
I belive "predictable" is the language used by the IETF draft.
> so there are several aspects:
>
> I see fragmentation id generation still as security critical:
> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> identifiers less predictable") I could patch my kernels and use the
> patch regardless of the machine being virtualized or not. It was not
> dependent on the hypervisor.
And now it's even easier - just patch the hypervisor, and all VMs
automatically benefit....
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...uniqueness. Also fragmentation
> ids should not be discoverable,
I belive "predictable" is the language used by the IETF draft.
> so there are several aspects:
>
> I see fragmentation id generation still as security critical:
> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> identifiers less predictable") I could patch my kernels and use the
> patch regardless of the machine being virtualized or not. It was not
> dependent on the hypervisor.
And now it's even easier - just patch the hypervisor, and all VMs
automatically benefit....
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...iscoverable,
>>
>> I belive "predictable" is the language used by the IETF draft.
>>
>>> so there are several aspects:
>>>
>>> I see fragmentation id generation still as security critical:
>>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
>>> identifiers less predictable") I could patch my kernels and use the
>>> patch regardless of the machine being virtualized or not. It was not
>>> dependent on the hypervisor.
>>
>> And now it's even easier - just patch the hyperv...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...iscoverable,
>>
>> I belive "predictable" is the language used by the IETF draft.
>>
>>> so there are several aspects:
>>>
>>> I see fragmentation id generation still as security critical:
>>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
>>> identifiers less predictable") I could patch my kernels and use the
>>> patch regardless of the machine being virtualized or not. It was not
>>> dependent on the hypervisor.
>>
>> And now it's even easier - just patch the hyperv...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; >
> > I belive "predictable" is the language used by the IETF draft.
> >
> > > so there are several aspects:
> > >
> > > I see fragmentation id generation still as security critical:
> > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > identifiers less predictable") I could patch my kernels and use the
> > > patch regardless of the machine being virtualized or not. It was not
> > > dependent on the hypervisor.
> >
> > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; >
> > I belive "predictable" is the language used by the IETF draft.
> >
> > > so there are several aspects:
> > >
> > > I see fragmentation id generation still as security critical:
> > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > identifiers less predictable") I could patch my kernels and use the
> > > patch regardless of the machine being virtualized or not. It was not
> > > dependent on the hypervisor.
> >
> > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; >
> > I belive "predictable" is the language used by the IETF draft.
> >
> > > so there are several aspects:
> > >
> > > I see fragmentation id generation still as security critical:
> > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > identifiers less predictable") I could patch my kernels and use the
> > > patch regardless of the machine being virtualized or not. It was not
> > > dependent on the hypervisor.
> >
> > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...gt; >
> > I belive "predictable" is the language used by the IETF draft.
> >
> > > so there are several aspects:
> > >
> > > I see fragmentation id generation still as security critical:
> > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > identifiers less predictable") I could patch my kernels and use the
> > > patch regardless of the machine being virtualized or not. It was not
> > > dependent on the hypervisor.
> >
> > And now it's even easier - just patch t...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
..."predictable" is the language used by the IETF draft.
>>>>
>>>>> so there are several aspects:
>>>>>
>>>>> I see fragmentation id generation still as security critical:
>>>>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
>>>>> identifiers less predictable") I could patch my kernels and use the
>>>>> patch regardless of the machine being virtualized or not. It was not
>>>>> dependent on the hypervisor.
>>>>
>>>> And now it...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
..."predictable" is the language used by the IETF draft.
>>>>
>>>>> so there are several aspects:
>>>>>
>>>>> I see fragmentation id generation still as security critical:
>>>>> When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
>>>>> identifiers less predictable") I could patch my kernels and use the
>>>>> patch regardless of the machine being virtualized or not. It was not
>>>>> dependent on the hypervisor.
>>>>
>>>> And now it...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...t; is the language used by the IETF draft.
> > > >
> > > > > so there are several aspects:
> > > > >
> > > > > I see fragmentation id generation still as security critical:
> > > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > > > identifiers less predictable") I could patch my kernels and use the
> > > > > patch regardless of the machine being virtualized or not. It was not
> > > > > dependent on the hypervisor.
> > > >
> > >...
2015 Jan 28
0
[PATCH 1/3] ipv6: Select fragment id during UFO/GSO segmentation if not set.
...t; is the language used by the IETF draft.
> > > >
> > > > > so there are several aspects:
> > > > >
> > > > > I see fragmentation id generation still as security critical:
> > > > > When Eric patched the frag id generator in 04ca6973f7c1a0d ("ip: make IP
> > > > > identifiers less predictable") I could patch my kernels and use the
> > > > > patch regardless of the machine being virtualized or not. It was not
> > > > > dependent on the hypervisor.
> > > >
> > >...