2 ms·
Most firewalls can be configured to block packets with a TTL greater than the route hop count back or simply never allow traffic through even if the TTL is the
by ZephyrP 15y ago
Most firewalls can be configured to block packets with a TTL greater than the route hop count back or simply never allow traffic through even if the TTL is the hop count + X (where X is distance to internal host, presumably 1)
I didn't mean to imply TTL incrementation was magic remote root.
As far as SSL, you're right in that it is a bit tangential. I'm just trying to illustrate the huge security flaws that, in my eyes, stand in front of "can someone sniff my traffic".
- tptacek 15y agoWhat huge security flaws in TLS are you referring to? (One of my business partners is the author of firewalk).
- ZephyrP 15y agoI'm a mere pup in San Francisco, you're Thomas Ptacek. You probably have a wikipedia page and personal islands. I could suffer an untimely fate if you so much as looked at me wrong. What I mean to say is that your authority is better than mine on this - so if you think SSL is secure, then I'll start telling people SSL is secure. I just think the numerous vulnerabilities unearthed so far, ranging from the eminently practical (Compromise a CA!) to the blindingly obvious (SSLStrip) constitute a poor record.
- tptacek 15y agoNot the response I was going for; just wondering if you meant policy stuff like CA's or protocol stuff.