From owner-freebsd-security Mon Apr 16 12: 6:36 2001 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-63-207-60-27.dsl.lsan03.pacbell.net [63.207.60.27]) by hub.freebsd.org (Postfix) with ESMTP id 9984A37B43F; Mon, 16 Apr 2001 12:06:30 -0700 (PDT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 3B228678B7; Mon, 16 Apr 2001 12:06:30 -0700 (PDT) Date: Mon, 16 Apr 2001 12:06:30 -0700 From: Kris Kennaway To: Darren Reed Cc: Kris Kennaway , Mike Silbersack , Mark T Roberts , freebsd-security@FreeBSD.ORG, net@FreeBSD.ORG Subject: Re: non-random IP IDs Message-ID: <20010416120630.C10023@xor.obsecurity.org> References: <20010416024805.A688@xor.obsecurity.org> <200104161836.EAA03291@caligula.anu.edu.au> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="TYecfFk8j8mZq+dy" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <200104161836.EAA03291@caligula.anu.edu.au>; from avalon@coombs.anu.edu.au on Tue, Apr 17, 2001 at 04:36:15AM +1000 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --TYecfFk8j8mZq+dy Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Tue, Apr 17, 2001 at 04:36:15AM +1000, Darren Reed wrote: > You should optimize it for mod being 2^n-1 (or make that a requirement). I'm afraid I don't have time to look at this right now. Perhaps it can be revisited (the sysctl defaults to off for now), or Niels Provos may be interested in the idea. > Also, drop the HTONS statements, they no longer make sense. Before ip_id > was a counter and so it made sense (sorta) to change its byte ordering to > network. Now it's just a random number so there is no longer any need. Well, it still has wrapping properties like a network-order counter, i.e. the algorithm attempts to order the output so that it doesn't wrap within the segment lifetime. That would be lost without using HTONS. Kris --TYecfFk8j8mZq+dy Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE620K1Wry0BWjoQKURAn72AJ9LgQ5HdeYEA09g3tA15l62W75dYwCg9pZd g3J2gozaTEXPWVstnZjh9ts= =LYF5 -----END PGP SIGNATURE----- --TYecfFk8j8mZq+dy-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message