security-misc icon indicating copy to clipboard operation
security-misc copied to clipboard

The claim about DSACK causing security issues is not actually backed by evidence

Open mikkorantalainen opened this issue 3 years ago • 2 comments

The comment here

https://github.com/Kicksecure/security-misc/blob/c19942f72b8d74056dd8da8c3cd9ac7e0fbe8991/etc/sysctl.d/tcp_sack.conf#L1-L2

makes it appear as if using DSACK would be a security problem. However, the discussion linked doesn't seem to provide any evidence for this. The linked SUSE material only speaks about disabling DSACK in 10 Gbit networks to reduce CPU usage.

mikkorantalainen avatar Jul 01 '22 13:07 mikkorantalainen

https://forums.whonix.org/t/disabling-tcp-sack-dsack-fack/8109/10

adrelanos avatar Jul 03 '22 10:07 adrelanos

//cc @madaidan

adrelanos avatar Jul 03 '22 10:07 adrelanos

See PR https://github.com/Kicksecure/security-misc/pull/122 for resolution of this issue.

raja-grewal avatar Mar 30 '23 08:03 raja-grewal

Thanks!

adrelanos avatar Mar 31 '23 08:03 adrelanos

//cc @madaidan

adrelanos avatar May 06 '23 07:05 adrelanos

Still some leftovers here: https://github.com/Kicksecure/security-misc/blob/master/README.md?plain=1#L385

Would you like to update?

adrelanos avatar May 06 '23 07:05 adrelanos

See PR https://github.com/Kicksecure/security-misc/pull/126

raja-grewal avatar May 15 '23 16:05 raja-grewal

Thanks, merged!

adrelanos avatar May 15 '23 16:05 adrelanos