Re: interception proxies

From: Joe Touch (touch@ISI.EDU)
Date: Wed Apr 12 2000 - 14:51:28 MDT


"Dick St.Peters" wrote:
>
> Would you settle for "The IP spec authors didn't have enough foresight
> to foresee a need to rewrite source addresses" ? :)
>
> Whatever anyone thinks of it, people are doing it. On the right are
> people saying it is immoral, evil, and dangerous, not to mention
> prohibited by the gods, and they refuse to talk about it. On the left
> are people doing it, each their own way because there is no standard
> and not even any public discussion.

Intercepting connections and sourcing packets with addresses not owned
by you (or within your stub subnet) violates one of the few standards we
have (STD003 - the combination of RFCs 1122 and 1123).

Intercepting connections by rewriting IP headers in a gateway violates a
proposed staandard (RFC 1812).

It is not immoral, evil or dangerous; there are standards (existing and
proposed), and they are being violated.

Joe



This archive was generated by hypermail 2b29 : Thu Nov 18 2004 - 11:21:28 MST