Re: 192.168 - why?
- From: David Schwartz <davids@xxxxxxxxxxxxx>
- Date: Sat, 26 Jul 2008 21:49:08 -0700 (PDT)
On Jul 26, 5:20 pm, Joe Pfeiffer <pfeif...@xxxxxxxxxxx> wrote:
David Schwartz <dav...@xxxxxxxxxxxxx> writes:
On Jul 25, 9:10 pm, Joe Pfeiffer <pfeif...@xxxxxxxxxxx> wrote:
True, but they're in a league where the reason to use non-routable IP
addresses is to limit external access -- another, very valid, reason.
I don't think so. It's too easy for one machine somewhere to be
compromised, allowing someone to proxy to any internal address. You
can't let one compromise turn into hundreds anyway. I honestly think
this is one of the worst arguments for using non-routable addresses.
You're giving the argument for no machines to be externally visible at
all. If you've got to have outside access, only allow it to a few,
tightly controlled machines.
No, I'm giving the argument for the protection to not be the non-
routability of the IP addresses but the security of the machines. You
can't count on non-routability ensuring the machines aren't
accessible.
I'm saying if your machines are secured properly, they are only
slightly more secure on unroutable addresses. And if they're not
secure, putting them on unroutable addresses won't make them secure.
If you count on unroutable addresses to make your machines secure, you
have a "one weak link compromises all" system. All that has to happen
is someone somehow compromises one inside machine and an attacker can
get around the unroutability of *all* machines. This compromise can be
any of a large number of things, including software on a "demo CD"
that someone runs on a machine they don't particularly care about and
that you put on your unroutable addresses because you don't trust it.
You can't have it both ways. You can't say "I'll dump all my untrusted
machines on my inside network so I don't have to really secure them
properly" and "I'll put my most important stuff that I really need to
be secure on my inside network because nobody can get to it".
You don't store your gold in the sewer.
DS
.
- References:
- 192.168 - why?
- From: Antonio Macchi
- Re: 192.168 - why?
- From: Lew Pitcher
- Re: 192.168 - why?
- From: AZ Nomad
- Re: 192.168 - why?
- From: Chris \"Saundo\" Saunderson
- Re: 192.168 - why?
- From: AZ Nomad
- Re: 192.168 - why?
- From: Joe Pfeiffer
- Re: 192.168 - why?
- From: David Schwartz
- Re: 192.168 - why?
- From: Joe Pfeiffer
- 192.168 - why?
- Prev by Date: Re: troubleshooting
- Next by Date: Re: troubleshooting
- Previous by thread: Re: 192.168 - why?
- Next by thread: Re: 192.168 - why?
- Index(es):
Relevant Pages
|