Re: TCP/IP offload: security implications

From: Bernd Eckenfels (ecki-news2002-02@lina.inka.de)
Date: 02/28/02


From: Bernd Eckenfels <ecki-news2002-02@lina.inka.de>
Date: 28 Feb 2002 18:55:06 GMT

In comp.security.misc Richard Masoner <nospam@masoner.net> wrote:
> I did receive one response from a developer familiar with these
> devices saying that if the state machines get stuck, then it's a
> simple matter to just reset everything and go on your way. I didn't
> ask if you lose your TCP session when that happens.

You do not lose TCP Sessions if IP Packets gets dropped. Or do you think those
cards do TCP Sockets, too?

I only know about SSL Accelerators who actually do TCP Sockets, but those
cards for sure have firmware.

> Still, what happens if these Intel or Adaptec "protocol accelerators"
> are used in edge servers and it's discovered the protocol
> implementation is vulnerable? Is it a reasonable risk to think about?

There is no problem with this for the user. You ak Intel to give you a fixed
model, thats what the dealers obligation to give you product gurantee is all
about.

Greetings
Bernd