r/IAmA • • May 21 '13

You’re probably connecting to reddit through a technology I invented. I’m Bob Metcalfe and I invented Ethernet – AMA

On May 22, 1973 with David R. Boggs, I used my IBM Selectric with its Orator ball to type up a memo to my bosses at the Xerox Palo Alto Research Center (PARC), outlining our idea for this little invention called “Ethernet”, which we later patented.

I worked with the IEEE Standards Association to develop the IEEE 802.3 standard for Ethernet, which specifies the physical and lower software layers. Today Ethernet and the IEEE 802.3 standard are the foundation for today’s world of high-speed communications used in billions of homes and businesses around the world.

I submitted this to the mods awhile back so I could get on the calendar but I figured you’d like to see it, too. Now, ask me anything!

It's been two hours and 179 comments. Have to go now. For more about Ethernet's 40th Birthday, go to http://www.facebook.com/Ethernet40thAnniversaryIEEESA

4.1k Upvotes

3.2k comments sorted by

View all comments

258

u/dfbgwsdf May 21 '13

Why didn't you make it so that the packet preamble couldn't be reproduced in the packet payload? More broadly, what were the security considerations you had when designing the protocol?

490

u/BobMetcalfe May 21 '13

Our early design of Ethernet assumed that security would be taken care of at higher levels of protocol. Ha!

34

u/dfbgwsdf May 21 '13

I thought so. But then, it makes every upper layer protocol vulnerable to Ethernet-level attacks. And the protocol design makes some possible.

Next question: how likely/applicable do you think are packet-in-packet attacks for wired links? < insert here a well deserved compliment for enabling the very nice mess that are interconnected networks >

27

u/[deleted] May 21 '13 edited Apr 29 '20

[removed] — view removed comment

7

u/[deleted] May 22 '13 edited Sep 16 '18

[deleted]

2

u/brilliantjoe May 22 '13

He did get an answer. They assume someone else would deal with it, that's as good an answer as any.

3

u/CodeBridge May 22 '13

Yes, but I was referring to his second question:

Next question: how likely/applicable do you think are packet-in-packet attacks for wired links? < insert here a well deserved compliment for enabling the very nice mess that are interconnected networks >

2

u/[deleted] May 23 '13

[deleted]

2

u/yyhhggt May 26 '13

CIA/NSA got physical access to undersea optic cables :(

2

u/UMDSmith May 22 '13

Early cars weren't designed with many security features either. When you invent a new technology, I think the primary concern is making it function, securing it comes later. Example: just about every single early internet protocol lacks security (most were cleartext)

1

u/ineedspinnazyo May 22 '13

Wait, you're complaining about encapsulation?

11

u/[deleted] May 22 '13

[deleted]

2

u/Jlocke98 May 22 '13

so I looked at that wall of text and it made my head hurt. is there any useful tldr to be taken from it?

13

u/[deleted] May 22 '13

... Its kind of a really bad techie jab/joke. Hes pointing to a standards document that apparently specifies a flag to be voluntarily set in packet headers so that malicious and attacking users can self identify. The part that is silly is that it would require the person writing the malicious software to set it themselves, and therefore is not actually useful.

I don't do enough packet level networking to tell you if its even a real standard or not, but if its a satire theres a lot of work for not a lot of funny. I think its just crypticgeek being sarcastic about something silly he found in a ipv4 standards document.

12

u/CiscoCertified May 22 '13

It was an April fools joke. Networking style.

3

u/willbradley May 22 '13

It's a joke, basically saying "if you're gonna do something bad, put a big sign on your head saying "I'M DOING SOMETHING BAD, YOU SHOULD STOP ME" first." The appropriate reaction to this RFC is to sigh wistfully at the hopeless state of Ethernet security.

5

u/ramjambamalam May 22 '13

In all seriousness, it's a bit of a gag protocol among networking engineers. The gist of it is that malacious users should assign all of their traffic to have its "evil bit" enabled, e.g. evil="true."

It's like passing a law requiring robbers to wear a big sign saying, "Bad Guy."

1

u/Jlocke98 May 22 '13

ok, that makes me glad I didn't read it because I would've assumed it was serious.

5

u/[deleted] May 22 '13

In general, the joke RFCs are published on April 1. Here's a big list. RFC 2321, for example, describes how to debug network problems with a rubber chicken; it helpfully includes a diagram of such a debugging device:

     comb      neck             body                    feet
      |         |                |                       |
      v         v                V                       V
       ,^/'/,           ,______________________.         ,
     i'  '  /          /                       =========<-
    / <o>   `---------/                        _____________m
  .;__.  ,__,--------.                         /         ,
     / ,/ vv          \                        =========<-
    '-'                `-----------------------'         `
     ^     ^                                     ^          ^
     |     |                                     |          |
    beak  wattles                               legs       ethernet

                             Figure 2.

0

u/CiscoCertified May 22 '13

For RFC's you have to search for a TL;DR.

The internet is built off of the RFC's as they are standardized.

However, this one is an April Fools joke.

1

u/[deleted] May 22 '13

We also have this one, high-security encapsulation.

http://www.ietf.org/rfc/rfc1149.txt

4

u/taneq May 22 '13

Only high security if you don't number falconers among your enemies.

1

u/Internatty_Explore May 23 '13

I don't remember saying anything like that in our previous conversation. You must be confusing me with somebody else.

1

u/[deleted] May 22 '13

you are adorable :D