paranoia

Edwin Groothuis edwin at mavetju.org
Wed Feb 16 18:53:30 PST 2005


On Wed, Feb 16, 2005 at 09:35:50PM -0800, Andrew Heyn wrote:
> I always see people replace their IPs with fake replacements.
> Is this paranoia really warranted?  Why not disconnect the cat5 if you want
> to do this?

If they're smart and know what they are doing, it will make things
easier to read: Machine A and Machine B are easier to recognize
than 192.218.32.34 and 129.218.34.32.

If they are not smart or misinformed, it will things impossible to
understand what is going on: x.y.z.35 and x.y.z.24 is totally the
wrong anonymousation[sp] of 1.2.3.35 and 5.6.7.24. It will also
give the wrong assumptions when you think it are both public addresses
while one is, or both are, private RFC addresses.

And than the third group who complain that their DNS server isn't
properly working and then give ns1.exmaple.org and test.example.org
because they want to anonymize it :-)

If they want to be paranoid, let them be. It will only make debugging
harder because they don't give the raw data.

Edwin
-- 
Edwin Groothuis      |            Personal website: http://www.mavetju.org
edwin at mavetju.org    |          Weblog: http://weblog.barnet.com.au/edwin/


More information about the freebsd-net mailing list