Re: Bug#520668: TCP SYN cookies and Bug #520668

2010-02-14 Thread Craig Small
On Sat, Feb 13, 2010 at 04:08:48PM +0100, Bastian Blank wrote: On Sun, Feb 14, 2010 at 12:42:09AM +1100, Craig Small wrote: You forgot to mail the maintainer of the package you change the configuration for. There are several packages now who applies various changes and this are all global

Re: TCP SYN cookies and Bug #520668

2010-02-13 Thread Bastian Blank
On Sun, Feb 14, 2010 at 12:42:09AM +1100, Craig Small wrote: Before I make this change, I am emailling debian-devel for comments. I am looking in particular for information about why it could be harmful (if it is). You forgot to mail the maintainer of the package you change the configuration

Re: TCP SYN cookies and Bug #520668

2010-02-13 Thread Ben Hutchings
On Sat, 2010-02-13 at 16:08 +0100, Bastian Blank wrote: On Sun, Feb 14, 2010 at 12:42:09AM +1100, Craig Small wrote: Before I make this change, I am emailling debian-devel for comments. I am looking in particular for information about why it could be harmful (if it is). You forgot to

Re: TCP SYN cookies and Bug #520668

2010-02-13 Thread Marco d'Itri
On Feb 13, Ben Hutchings b...@decadent.org.uk wrote: I'm going to agree with Bastian here. Single-user systems won't need this and system administrators can make their own choice. I do not really disagree with your argument, but can you or the other people who oppose this explain more clearly

Re: TCP SYN cookies and Bug #520668

2010-02-13 Thread Ben Hutchings
On Sat, 2010-02-13 at 18:24 +0100, Marco d'Itri wrote: On Feb 13, Ben Hutchings b...@decadent.org.uk wrote: I'm going to agree with Bastian here. Single-user systems won't need this and system administrators can make their own choice. I do not really disagree with your argument, but can

Re: TCP SYN cookies and Bug #520668

2010-02-13 Thread Marco d'Itri
On Feb 13, Ben Hutchings b...@decadent.org.uk wrote: The upstream default is that they are disabled. The onus is on proponents to argue why this should be changed. The proposed rationale for the change is that SYN cookies are not used until the SYN queue is full and at that point it is more

Re: TCP SYN cookies and Bug #520668

2010-02-13 Thread Paul Wise
On Sun, Feb 14, 2010 at 2:08 AM, Marco d'Itri m...@linux.it wrote: On Feb 13, Ben Hutchings b...@decadent.org.uk wrote: The upstream default is that they are disabled.  The onus is on proponents to argue why this should be changed. The proposed rationale for the change is that SYN cookies

Re: TCP SYN cookies and Bug #520668

2010-02-13 Thread Marco d'Itri
On Feb 14, Paul Wise p...@debian.org wrote: Kinda a dissapointing thread, but it reveals a few points: I see more handwaving than points. -- ciao, Marco signature.asc Description: Digital signature