<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security</title>
	<atom:link href="http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/</link>
	<description>Threat News and Information Direct from the Experts</description>
	<lastBuildDate>Thu, 09 Feb 2012 20:16:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security &#8211; Security Threat Research News</title>
		<link>http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/comment-page-1/#comment-36017</link>
		<dc:creator>IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security &#8211; Security Threat Research News</dc:creator>
		<pubDate>Mon, 07 Dec 2009 04:38:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.trendmicro.com/?p=20039#comment-36017</guid>
		<description>[...] from: TrendLabs &#124; Malware Blog &#8211; by Trend MicroIPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security           Ben April (Advanced Threat Researcher) @ TrendLabs &#124; Malware Blog - by Trend Micro [...]</description>
		<content:encoded><![CDATA[<p>[...] from: TrendLabs | Malware Blog &#8211; by Trend MicroIPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security           Ben April (Advanced Threat Researcher) @ TrendLabs | Malware Blog &#8211; by Trend Micro [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Phocean.net &#187; IPv6 tunneling and security</title>
		<link>http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/comment-page-1/#comment-34687</link>
		<dc:creator>Phocean.net &#187; IPv6 tunneling and security</dc:creator>
		<pubDate>Wed, 04 Nov 2009 10:11:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.trendmicro.com/?p=20039#comment-34687</guid>
		<description>[...] Follow this link. [...]</description>
		<content:encoded><![CDATA[<p>[...] Follow this link. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IPv6 Tunneling-Protokolle – Anwender sollten die Risiken kennen » markus-arlt.de</title>
		<link>http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/comment-page-1/#comment-34456</link>
		<dc:creator>IPv6 Tunneling-Protokolle – Anwender sollten die Risiken kennen » markus-arlt.de</dc:creator>
		<pubDate>Wed, 28 Oct 2009 22:48:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.trendmicro.com/?p=20039#comment-34456</guid>
		<description>[...] diesem Hinweis auf Sicherheitsrisiken möchte Ben April allerdings niemanden davon abhalten, IPv6 auszuprobieren. Im Gegenteil, er rät jedem, das [...]</description>
		<content:encoded><![CDATA[<p>[...] diesem Hinweis auf Sicherheitsrisiken möchte Ben April allerdings niemanden davon abhalten, IPv6 auszuprobieren. Im Gegenteil, er rät jedem, das [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sabahattin Gucukoglu</title>
		<link>http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/comment-page-1/#comment-34386</link>
		<dc:creator>Sabahattin Gucukoglu</dc:creator>
		<pubDate>Tue, 27 Oct 2009 15:42:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.trendmicro.com/?p=20039#comment-34386</guid>
		<description>I&apos;m not all scared.  My server&apos;s public IPv4 address is already known; there is no egress on most ISPs; people can already do horrible things to me and my server.  That is no different with assigned teredo and/or 6to4.  But, yeah, 6in4 is the more &quot;Secure&quot; alternative since you can have trust rules leading from your end to the gateway&apos;s end work fine (no unsolicited traffic).

Remember, part of what makes Teredo and/or 6to4 so damn useful is that we can do direct host-to-host communication with routable blocks of IPv6.  So we get IPv4&apos;s routing advantages without the &apos;orrible NAT/ALG/crap (minus a bit of efficiency for smaller payload sizes).  I agree it&apos;s something to think about, but not too hard.  Remember when we had ::/96 for compatible IPv4 addresses?  Now that *would* have been anarchy (and there are still vestiges of that left in the various hideous translation proposals being pushed by all and sundry).

Cheers,
Sabahattin</description>
		<content:encoded><![CDATA[<p>I&apos;m not all scared.  My server&apos;s public IPv4 address is already known; there is no egress on most ISPs; people can already do horrible things to me and my server.  That is no different with assigned teredo and/or 6to4.  But, yeah, 6in4 is the more &quot;Secure&quot; alternative since you can have trust rules leading from your end to the gateway&apos;s end work fine (no unsolicited traffic).</p>
<p>Remember, part of what makes Teredo and/or 6to4 so damn useful is that we can do direct host-to-host communication with routable blocks of IPv6.  So we get IPv4&apos;s routing advantages without the &apos;orrible NAT/ALG/crap (minus a bit of efficiency for smaller payload sizes).  I agree it&apos;s something to think about, but not too hard.  Remember when we had ::/96 for compatible IPv4 addresses?  Now that *would* have been anarchy (and there are still vestiges of that left in the various hideous translation proposals being pushed by all and sundry).</p>
<p>Cheers,<br />
Sabahattin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joe Klein</title>
		<link>http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/comment-page-1/#comment-34381</link>
		<dc:creator>Joe Klein</dc:creator>
		<pubDate>Tue, 27 Oct 2009 14:52:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.trendmicro.com/?p=20039#comment-34381</guid>
		<description>Ben, IPv6 is a great protocol with many security features, not  just IPSec, but until we have built end-to-end native IPv6 connections and rid ourselves of IPv4, the transition techniques you describe above will be a ongoing threat to the network integrity of all organizations. But your blog entry only touched on a very small surface of the threat. 

In my speech at DOJOSec (http://blog.saecur.com/2009/07/saecur-dojosec-june-2009-joe-klein.html), I describe more tunnels and problems that need to be addresses today, prior to implementing IPv6. I also have a site which contains the last 5 years  of my IPv6 security presentations ( http://sites.google.com/site/ipv6security/Joe Klein)

Lastly, DOJOCon (www.dojocon.org), a Security conference to benefit Hackers For Charity (http://www.hackersforcharity.org/), is scheduled to stream my presentation sometime after 3:50pm EST, Friday November 6th, 2009.  Check out the website to learn more about the conference. And don’t forget to donate to “Hackers for Charity”!

And Ben, keep up the great work on the blog! It’s worth the read.

Joe Klein, CISSP...
North American IPv6 Task Force, Security SME</description>
		<content:encoded><![CDATA[<p>Ben, IPv6 is a great protocol with many security features, not  just IPSec, but until we have built end-to-end native IPv6 connections and rid ourselves of IPv4, the transition techniques you describe above will be a ongoing threat to the network integrity of all organizations. But your blog entry only touched on a very small surface of the threat. </p>
<p>In my speech at DOJOSec (<a href="http://blog.saecur.com/2009/07/saecur-dojosec-june-2009-joe-klein.html" rel="nofollow">http://blog.saecur.com/2009/07/saecur-dojosec-june-2009-joe-klein.html</a>), I describe more tunnels and problems that need to be addresses today, prior to implementing IPv6. I also have a site which contains the last 5 years  of my IPv6 security presentations ( <a href="http://sites.google.com/site/ipv6security/Joe" rel="nofollow">http://sites.google.com/site/ipv6security/Joe</a> Klein)</p>
<p>Lastly, DOJOCon (www.dojocon.org), a Security conference to benefit Hackers For Charity (<a href="http://www.hackersforcharity.org/" rel="nofollow">http://www.hackersforcharity.org/</a>), is scheduled to stream my presentation sometime after 3:50pm EST, Friday November 6th, 2009.  Check out the website to learn more about the conference. And don’t forget to donate to “Hackers for Charity”!</p>
<p>And Ben, keep up the great work on the blog! It’s worth the read.</p>
<p>Joe Klein, CISSP&#8230;<br />
North American IPv6 Task Force, Security SME</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: UnderForge of Lack &#187; Blog Archive &#187; 2009.10.27 火曜日 （たぶん）縮刷版</title>
		<link>http://blog.trendmicro.com/ipv6-tunneling-protocols-good-for-adoption-not-so-hot-for-security/comment-page-1/#comment-34360</link>
		<dc:creator>UnderForge of Lack &#187; Blog Archive &#187; 2009.10.27 火曜日 （たぶん）縮刷版</dc:creator>
		<pubDate>Tue, 27 Oct 2009 00:14:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.trendmicro.com/?p=20039#comment-34360</guid>
		<description>[...]  ---------- IPv6 と 6to4プロトコル  IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security [...]</description>
		<content:encoded><![CDATA[<p>[...]  &#8212;&#8212;&#8212;- IPv6 と 6to4プロトコル  IPv6 Tunneling Protocols: Good for Adoption, Not So Hot for Security [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

