IP Storage Spec Gets the Boot | eWeek

IP Storage Spec Gets the Boot

Written By
eWEEK EDITORS
eWEEK EDITORS
Jan 9, 2003
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A draft specification for how future IP storage hardware will boot up encountered an obstacle this week: Microsoft security.

The document, “Bootstrapping Clients Using the iSCSI Protocol,” was voted down by the Internet Engineering Steering Groups IP Storage Working Group. The vote was nine to two, with an abstention by renowned AT&T Corp. security expert Steve Bellovin.

In its current form, the document discusses such security mechanisms as Dynamic Host Configuration Protocol authentication, SLPv2 and IPsec. But IP storage systems are expected to connect largely to Windows servers, and Windows Preboot Execution Environment, or PXE, is inherently insecure, one of the voters wrote, anonymously.

“PXE security is rarely enabled in practice, and this makes it possible for a rogue PXE server to reformat the hard disks of machines booting within an enterprise network,” the voter commented. Boot security is “potentially one of the most lethal security vulnerabilities existing today [and] was the topic of a briefing to the National Security Council.”

“Its an interesting Microsoft capability/problem,” said Allison Mankin, IESG Transport Director for the working group, who works as a Lucent Technologies Inc./Bell Labs researcher. “iSCSI is a disk system thats often used in the context of PXE. [The draft] didnt do anything to improve on the PXE security,” she said.

However, she and the working group leaders “are hopeful that you could do a good job of this in a month,” and that it wont delay the main iSCSI draft. The main draft was also voted down but because of more minor concerns that are simpler to fix, and that will become a Proposed Standard next week, Mankin said, in Washington, D.C.

Microsoft Corp. officials, in Redmond, Wash., did not comment on the PXE criticism.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.