6 ms·
Clever, yes. But this will break in presence of middle-boxen that rewrite IP-ID [1] and/or TCP-SEQ/ACK [2] numbers (SSL inspection firewalls, WAN optimizers, ol
by nousermane 4y ago
Clever, yes. But this will break in presence of middle-boxen that rewrite IP-ID [1] and/or TCP-SEQ/ACK [2] numbers (SSL inspection firewalls, WAN optimizers, older satellite modems, even some particularly bad carrier-grade NAT devices).
[1] https://en.wikipedia.org/wiki/IPv4#Identification https://en.wikipedia.org/wiki/IPv4#Identification
[2] https://en.wikipedia.org/wiki/Transmission_Control_Protocol#TCP_segment_structure https://en.wikipedia.org/wiki/Transmission_Control_Protocol#...
- cryptonector 4y agoYes, putting the HMAC in the IP ID field is brittle. Maybe a TCP option could be used.