5 ms·
* Secure handshaking requires interactivity, unless you share secrets with your actual partner (no, your CA trust store isn't enough) in advance. So your first
by Ao7bei3s 8y ago
* Secure handshaking requires interactivity, unless you share secrets with your actual partner (no, your CA trust store isn't enough) in advance. So your first packet would leak it.
* To return ICMP error messages ("destination unreachable"), otherwise you'd have long timeouts.
* Ratelimiting outside the server (e.g. DDOS protection). Many ISPs do actually filter source IPs. (Of course you can't on the backbone, any there are plenty shady AS.)
* Leaving it off won't help against correlation attacks.
* Most applications will need it, so it makes sense to have it in the network layer instead of coming up with incompatible implementations above.
- ra1n85 8y ago+RPF requires it to help prevent spoofing (BCP 38)
- ggm 8y agoLike AS PATH this is one of the reasons people say but like path security in BGP, its not what people actually do very much. I like BCP38 and I like MANRS but.. traction is hard here. I was making statements about the road not taken: we have dst IP in the packets, from before BCP existed.
- caf 8y agoIn our thought-experiment world where each address has a public key that can be used to encrypt the payload data destined for it, the public key of the source can also be used to sign the data, ensuring the sender address isn't spoofed.
- ra1n85 8y agoWhat validates that - the destination or intermediate devices? Spoofing is often just a means for volumetric DDoS attacks - if the destination is responsible for validate sources then we’re no better off there.
- caf 8y agoPresumably it would be validated by the destination, but that doesn't matter. The reason spoofing matters so much for volumetric DDOS attacks isn't due to spoofing the traffic sent directly to the target - it's because the target is spoofed as the source address in traffic sent to third-party amplifiers, that respond to the target. If the third party amplifiers in this scenario can validate that the traffic is spoofed, it cuts out amplification attacks.
- geocar 8y agoYour router requires it, but nobody else on the Internet needs it.