Sure, this time it's a software design bug in the endpoints, but next time it might be a cosmic ray, or an evil middleman, or a buggy proxy. If data isn't encrypted and authenticated, then you shouldn't care what form it arrives in.
Sure, this time it's a software design bug in the endpoints, but next time it might be a cosmic ray, or an evil middleman, or a buggy proxy. If data isn't encrypted and authenticated, then you shouldn't care what form it arrives in.
Yes, it needs a failure detection mechanism, because next time it might be a cosmic ray. But encryption and authentication alone doesn't help necessarily.
You're referring to things that happen in a different OSI layer
To lump this into an existing category of bugs, syn cookies are a kind of HMAC, only the implementation is custom and nonstandard. It isn't a surprise that a bespoke HMAC leaks, but to the credit of kernel developers syn cookies the initial 1996 specification pre-dates the common understanding. (But to its demerit, it looks like the DJB spec (http://cr.yp.to/syncookies.html) would have not had this issue, since the MSS was encoded in the top bits of the cookie and not the bottom bits.)