From owner-freebsd-net@FreeBSD.ORG Thu Apr 4 21:52:33 2013 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.FreeBSD.org [8.8.178.115]) by hub.freebsd.org (Postfix) with ESMTP id 0D1B0744; Thu, 4 Apr 2013 21:52:33 +0000 (UTC) (envelope-from kevin@your.org) Received: from mail.your.org (mail.your.org [IPv6:2001:4978:1:2::cc09:3717]) by mx1.freebsd.org (Postfix) with ESMTP id DBD44F48; Thu, 4 Apr 2013 21:52:32 +0000 (UTC) Received: from mail.your.org (chi02.mail.your.org [204.9.55.23]) by mail.your.org (Postfix) with ESMTP id 61E4BF06C69; Thu, 4 Apr 2013 21:52:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=your.org; h=content-type :mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; s= selector1; bh=A8dajdB6OHx+NmbD+UhNhP4TyC8=; b=jPI0RBNXXjNjc2ZBIa 8zYxIXVVgNAqCyJ4kORqRu05C3a61YgAv9ZoRkN8s4aUbGPM2l03iTjU8QZlVyXK H9gYXJrvLXBch3pIjwZErV0QQ0N9VR45SqFZ7SahY7uU7BS1JFWrhZ2YSx6r9jwL nCUzrR+ym5nBVEWcBlSMEnJsM= DomainKey-Signature: a=rsa-sha1; c=nofws; d=your.org; h=content-type :mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; q=dns; s= selector1; b=MHv/eqGENWOIudaV2OBJ+ry/5TOmG0FlrLw7uinpxQhugtM63QO hq7tIhTy5ToUmIiJ7GwSv+b1e2e5A4fYW5QmbeEaLB3m1AxTfQ6OhwGpf6GrBy5O DpThSnEKPK5hJt72AsbZnN7CEQPIxCXUBBoC+Uk/tkfI5YBldeGtA2eU= Received: from vpn132.rw1.your.org (vpn132.rw1.your.org [204.9.51.132]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by mail.your.org (Postfix) with ESMTPSA id 2CEFCF06C5D; Thu, 4 Apr 2013 21:52:31 +0000 (UTC) Content-Type: text/plain; charset=us-ascii Mime-Version: 1.0 (Mac OS X Mail 6.3 \(1503\)) Subject: Re: Syncookies break with Windows 8 From: Kevin Day In-Reply-To: <510C4B17.4040509@freebsd.org> Date: Thu, 4 Apr 2013 16:52:31 -0500 Content-Transfer-Encoding: quoted-printable Message-Id: <3DABEC7E-78B8-49DE-9F76-0B96019E8424@your.org> References: <510C4424.4030701@networx.ch> <510C4B17.4040509@freebsd.org> To: Andre Oppermann X-Mailer: Apple Mail (2.1503) Cc: freebsd-net@freebsd.org X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 04 Apr 2013 21:52:33 -0000 On Feb 1, 2013, at 5:09 PM, Andre Oppermann wrote: >=20 > I'm working on a solution. Have to make sure that the chance to > crack a reduced cookie during its 30 seconds lifetime isn't too > high. That means involving our resident crypto experts for > verification. Hey, Andre! I know the security people have been pretty busy, but has there been any = progress on this? We're still running into the occasional complaint with = this issue. -- Kevin