Re: .gov support of DNSSEC

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
The Whitehouse OMB supposedly issued a memo telling government agences
to upgrade--they appear to have been duped by the Kaminsky thing.  I am
planning to get together people who want to sign a letter to the
Whitehouse asking to reverse this policy.  Contact me for details and to
contribute to the letter text.

The Kaminsky report created "urgency"; A frequent element of a scam is
to have such urgency that one can't stop to think about whether the
claims are legitimate or make sense. Professor Bruce Wedlock often
repeated "Always ask yourself 'Does this make sense?'" The Kaminsky
report, by the way, is entirely false regarding the discovery;  many
people have already noted that DJB discovered this attack in the 1990s.
Of course, the attack could have been forgotten and 'rediscovered', but
that isn't the case, either. I found a design report for Unbound
(developed by Nominet, Verisign, NLnet Labs, EP.NET (Bill Manning))
http://www.unbound.net/documentation/ietf67-design-02.pdf in which they
describe that "spoofed NS additionals confuse iterator".  This paper was
discussed at IETF 67, in November 2006, so one can't even say that DJB
discovered the attack in the 90's but it was forgotten and rediscovered
by Kaminsky.  Kaminsky just created a lot of "urgency", with the result 
of scaring people into adopting DNSSEC. 


[OT Note: BTW, for those still following the Bind Company (or Bind
Cartel as I like to call it), I have found evidence that Verisign is an
investor in Nominum, and that Paul Vixie is a founder of Nominum (well
known fact, but hard to find proof), and I have discovered that ISC and
Nominum share employees. I may put up a public wiki site for this, if
there's still interest.  I also need someone in the SF bay area to check
out some things, too--if anyone is willing to help, contact me offlist
--thx]

Back to DNSSEC: There are a number of problems with DNSSEC, besides the
one you just mentioned.  There are a number of attacks on DNSSEC,
including replay attacks that still allow caches to be poisoned with bad
data.

DNSSEC also enables new DDOS attacks, by merely forging DNSSEC requests
to DNSSEC domains. I haven't tested .gov yet, but one should be able to
get a fairly large response back.  A small query (perhaps 64bytes) can
get an up to an 8KB response with DNSSEC.

Deploying DNSSEC is a bad idea. 

I wonder how long before someone releases a tool to exploit DNSSEC
domains for a DDOS attack, like the "Rapid Enumeration Tool"  (RET)
released by Nominet. The RET exploits open recursors to sureptitiously
enumerate NSEC records.

 "The Rapid Enumeration Tool (RET) is designed to use DNSSEC NSEC
 records to enumerate quickly zone data whilst evading detection by
 systems which might be designed specifically to identify zone
 enumeration activity. It does this by using one or more open recursive
 resolvers to forward queries to the authoritative name servers for the
 zone. Each resolver is configured with its own 'personality', 
 specifying query rates, query failure/success ratio, proportions of
 query types, query name decoration, etc. This allows the RET to feed
 queries to each resolver, that are specifically tailored to match the
 queries that a resolver might typically send to the authoritative name
 server. Unlike other NSEC resource record 'walkers', the RET does not
 explicitly query for NSEC RRs to walk the zone. Instead, it combines a
 'walker' approach with a dictionary attack (combined with a random name
 generator for more awkward cases). This means that discernible
 artifacts in the pattern of queries that arrive at the authoritative
 servers should be minimised." -- from http://www.dnssec.net/software 



		--Dean

On Mon, 22 Sep 2008, Jason Frisvold wrote:

> Hi all,
> 
> I guess I've been meaning to join this list for some time, but since
> DJBDNS just seems to work, I haven't had a real need...  However, that
> may change.  It appears that the Federal Government has mandated a
> rollout of DNSSEC for all .gov domains.  They're spinning this as a
> way to be "sure" that you get to the proper government site, but fail
> to mention that without valid resolvers on the user end, there is
> still zero security.
> 
> Regardless, this may mean that DNSSEC is here to stay.  It's still a
> bit early, though, and the apparent mandate for IPv6 hasn't proven to
> make it any more popular either.
> 
> What is being done on the DJBDNS front, though?  I see mention of a
> new crypto DNS library, DNSCurve, though it appears that there is no
> current release.  Is this the answer to DNSSEC?  Will this be
> "compatible" with DNSSEC, or will I eventually be forced to move to
> other resolvers?
> 
> Thanks!
> 
> 

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.