2 ms·
I agree, it's not necessarily the right OSI layer we should be trying to secure. Unfortunately, NSA sabotaged IPv6 goal of "encrypting everything by default":
by tikums 13y ago
I agree, it's not necessarily the right OSI layer we should be trying to secure.
Unfortunately, NSA sabotaged IPv6 goal of "encrypting everything by default":
https://en.wikipedia.org/wiki/IPsec#Alleged_NSA_interference https://en.wikipedia.org/wiki/IPsec#Alleged_NSA_interference
Specifically,
"IPsec was originally required in IPv6 before RFC 6434 made it only a recommendation"
- wmf 13y agoGiven the current state of IPsec/IKE, making it "required" is pointless. AFAIK there is no standard for opportunistic session setup, so random hosts don't know how to speak IPsec to each other even if they both implement it.