> OTOH, anybody who truly cares about security is blocking _all_ IP > options at their border router, long before the packet is seen by any > firewall. Thereby breaking any number of useful things that can be done with things like timestamp options. If you really care about security, use bloody decent OSes so that you don't flippin' *need* to block IP options, you don't *need* a firewall! Options are there because they're useful and support valuable facilities. Block 'em if you like, but you'll get no sympathy from *me* when something breaks for you as a result. der Mouse mouseat_private 7D C8 61 52 5D E7 2D 39 4E F1 31 3E E8 B3 27 4B
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:09:05 PDT