And behold, the IEEE gods gave us 802.1AE. #MACsechttps://twitter.com/RichFelker/status/1009870219333062658 …
-
-
-
Replying to @RichFelker
It's actually pretty sweet. Linux has support for it in iproute2 + kernel.
1 reply 0 retweets 0 likes -
Replying to @troglobit
It's still a tool for letting people do something fundamentally wrong and insecure with a false sense that it's secure.
1 reply 0 retweets 0 likes -
Replying to @RichFelker
Um, it's encrypted, like IPsec? Maybe you mean 802.1X?
1 reply 0 retweets 0 likes -
Replying to @troglobit
Using IPsec for access control is another iteration of the same insecure design. You're granting access to any process that can make a connection from the magically-trusted host.
2 replies 0 retweets 0 likes -
Replying to @RichFelker
You're like my hero, so I will not pick a fight with you, but we're clearly talking about different things. I apologize for commenting in the first place and will stay out of your way. Take care
1 reply 0 retweets 1 like
OK, maybe so. FWIW I have no objection to using IPsec or similar tools as a privacy layer, but I do think it's really dangerous to think they suddenly make it safe to treat location-on-network as an access control method.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.