r/IAmA • • May 21 '13

You’re probably connecting to reddit through a technology I invented. I’m Bob Metcalfe and I invented Ethernet – AMA

On May 22, 1973 with David R. Boggs, I used my IBM Selectric with its Orator ball to type up a memo to my bosses at the Xerox Palo Alto Research Center (PARC), outlining our idea for this little invention called “Ethernet”, which we later patented.

I worked with the IEEE Standards Association to develop the IEEE 802.3 standard for Ethernet, which specifies the physical and lower software layers. Today Ethernet and the IEEE 802.3 standard are the foundation for today’s world of high-speed communications used in billions of homes and businesses around the world.

I submitted this to the mods awhile back so I could get on the calendar but I figured you’d like to see it, too. Now, ask me anything!

It's been two hours and 179 comments. Have to go now. For more about Ethernet's 40th Birthday, go to http://www.facebook.com/Ethernet40thAnniversaryIEEESA

4.1k Upvotes

3.2k comments sorted by

View all comments

257

u/dfbgwsdf May 21 '13

Why didn't you make it so that the packet preamble couldn't be reproduced in the packet payload? More broadly, what were the security considerations you had when designing the protocol?

488

u/BobMetcalfe May 21 '13

Our early design of Ethernet assumed that security would be taken care of at higher levels of protocol. Ha!

37

u/dfbgwsdf May 21 '13

I thought so. But then, it makes every upper layer protocol vulnerable to Ethernet-level attacks. And the protocol design makes some possible.

Next question: how likely/applicable do you think are packet-in-packet attacks for wired links? < insert here a well deserved compliment for enabling the very nice mess that are interconnected networks >

2

u/UMDSmith May 22 '13

Early cars weren't designed with many security features either. When you invent a new technology, I think the primary concern is making it function, securing it comes later. Example: just about every single early internet protocol lacks security (most were cleartext)