Re: .gov support of DNSSEC
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
The Whitehouse OMB supposedly issued a memo telling government agences to upgrade--they appear to have been duped by the Kaminsky thing. I am planning to get together people who want to sign a letter to the Whitehouse asking to reverse this policy. Contact me for details and to contribute to the letter text. The Kaminsky report created "urgency"; A frequent element of a scam is to have such urgency that one can't stop to think about whether the claims are legitimate or make sense. Professor Bruce Wedlock often repeated "Always ask yourself 'Does this make sense?'" The Kaminsky report, by the way, is entirely false regarding the discovery; many people have already noted that DJB discovered this attack in the 1990s. Of course, the attack could have been forgotten and 'rediscovered', but that isn't the case, either. I found a design report for Unbound (developed by Nominet, Verisign, NLnet Labs, EP.NET (Bill Manning)) http://www.unbound.net/documentation/ietf67-design-02.pdf in which they describe that "spoofed NS additionals confuse iterator". This paper was discussed at IETF 67, in November 2006, so one can't even say that DJB discovered the attack in the 90's but it was forgotten and rediscovered by Kaminsky. Kaminsky just created a lot of "urgency", with the result of scaring people into adopting DNSSEC. [OT Note: BTW, for those still following the Bind Company (or Bind Cartel as I like to call it), I have found evidence that Verisign is an investor in Nominum, and that Paul Vixie is a founder of Nominum (well known fact, but hard to find proof), and I have discovered that ISC and Nominum share employees. I may put up a public wiki site for this, if there's still interest. I also need someone in the SF bay area to check out some things, too--if anyone is willing to help, contact me offlist --thx] Back to DNSSEC: There are a number of problems with DNSSEC, besides the one you just mentioned. There are a number of attacks on DNSSEC, including replay attacks that still allow caches to be poisoned with bad data. DNSSEC also enables new DDOS attacks, by merely forging DNSSEC requests to DNSSEC domains. I haven't tested .gov yet, but one should be able to get a fairly large response back. A small query (perhaps 64bytes) can get an up to an 8KB response with DNSSEC. Deploying DNSSEC is a bad idea. I wonder how long before someone releases a tool to exploit DNSSEC domains for a DDOS attack, like the "Rapid Enumeration Tool" (RET) released by Nominet. The RET exploits open recursors to sureptitiously enumerate NSEC records. "The Rapid Enumeration Tool (RET) is designed to use DNSSEC NSEC records to enumerate quickly zone data whilst evading detection by systems which might be designed specifically to identify zone enumeration activity. It does this by using one or more open recursive resolvers to forward queries to the authoritative name servers for the zone. Each resolver is configured with its own 'personality', specifying query rates, query failure/success ratio, proportions of query types, query name decoration, etc. This allows the RET to feed queries to each resolver, that are specifically tailored to match the queries that a resolver might typically send to the authoritative name server. Unlike other NSEC resource record 'walkers', the RET does not explicitly query for NSEC RRs to walk the zone. Instead, it combines a 'walker' approach with a dictionary attack (combined with a random name generator for more awkward cases). This means that discernible artifacts in the pattern of queries that arrive at the authoritative servers should be minimised." -- from http://www.dnssec.net/software --Dean On Mon, 22 Sep 2008, Jason Frisvold wrote: > Hi all, > > I guess I've been meaning to join this list for some time, but since > DJBDNS just seems to work, I haven't had a real need... However, that > may change. It appears that the Federal Government has mandated a > rollout of DNSSEC for all .gov domains. They're spinning this as a > way to be "sure" that you get to the proper government site, but fail > to mention that without valid resolvers on the user end, there is > still zero security. > > Regardless, this may mean that DNSSEC is here to stay. It's still a > bit early, though, and the apparent mandate for IPv6 hasn't proven to > make it any more popular either. > > What is being done on the DJBDNS front, though? I see mention of a > new crypto DNS library, DNSCurve, though it appears that there is no > current release. Is this the answer to DNSSEC? Will this be > "compatible" with DNSSEC, or will I eventually be forced to move to > other resolvers? > > Thanks! > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000