Date: Mon, 16 Apr 2001 20:32:11 -0700 From: Julian Elischer <julian@elischer.org> To: Darren Reed <avalon@coombs.anu.edu.au> Cc: Kris Kennaway <kris@obsecurity.org>, Mike Silbersack <silby@silby.com>, Mark T Roberts <newsletter@marktroberts.com>, freebsd-security@FreeBSD.ORG, net@FreeBSD.ORG Subject: Re: non-random IP IDs Message-ID: <3ADBB93B.3C9DC3DE@elischer.org> References: <200104161836.EAA03291@caligula.anu.edu.au>
next in thread | previous in thread | raw e-mail | index | archive | help
Darren Reed wrote: > > In some mail from Kris Kennaway, sie said: > > > > > > --rwEMma7ioTxnRzrJ > > Content-Type: text/plain; charset=us-ascii > > Content-Disposition: inline > > Content-Transfer-Encoding: quoted-printable > > > > On Mon, Apr 16, 2001 at 02:03:11AM -0700, Kris Kennaway wrote: > > > > > Here's a patch ported from OpenBSD which randomizes this (supposedly > > > such that it respects the constraint of not wrapping within the > > > prescribed time period). I should wrap it in a sysctl, I guess. > > >=20 > > > http://www.freebsd.org/~kris/ipid.patch > > > > Okay, I did this and updated the patch, with the sysctl defaulting to > > off since the random algorithm does add some amount of overhead. > > > > > Comments? > > You should optimize it for mod being 2^n-1 (or make that a requirement). > > Also, drop the HTONS statements, they no longer make sense. Before ip_id > was a counter and so it made sense (sorta) to change its byte ordering to > network. Now it's just a random number so there is no longer any need. there is a site that calculates server uptime from these numbers. All the leading machines are freeBSD. When you do this it will no-longer be able to track us :-( what is the problem in having these numbers sequential? > > Darren > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-net" in the body of the message -- __--_|\ Julian Elischer / \ julian@elischer.org ( OZ ) World tour 2000-2001 ---> X_.---._/ v To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-net" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3ADBB93B.3C9DC3DE>