Caitlin Bestler | 20 Apr 2006 18:19
Favicon

RE: DDP/RDMAP Applicability

Derek Atkins wrote:
> I was asked to review the DDP/RDMAP specifications.  Here are
> my comments on draft-ietf-rddp-applicability-05.txt
> 

Typos noted and fixed. Thanks.

> 
> ----
> ----
> 
> Section 6.6 : Data Integrity Implications
> 
> CRC32 helps protect against accidental data corruption, but
> not intensional data corruption.  An attacker could easily
> intentionally corrupt the data and a CRC32 cannot detect
> that.  I recommend some stronger wording that an active
> attacker could easily subvert the CRC32, or at least
> additional text that explains that CRC32 only protects
> against accidental data corruption and not intensional data
> corruption. 
> 

Clarification on the types of corruption will be added.

> ----
> 
> Section 9 : Security considerations
> 
> The discussion of the steering tag doesn't discuss what
(Continue reading)


Gmane