Re: .gov support of DNSSEC
"Joe Baptista" <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Sep 22, 2008 at 6:09 PM, Dean Anderson <[email protected]> wrote: > The Whitehouse OMB supposedly issued a memo telling government agences > to upgrade--they appear to have been duped by the Kaminsky thing. I am > planning to get together people who want to sign a letter to the > Whitehouse asking to reverse this policy. Contact me for details and to > contribute to the letter text. I'll join in. I have already spoken out about this. Interesting side note to your discussion here. While one branch of government goes plunging into the abyss defined by the DNSSEC nonsense. Another branch has put the brakes on ICANN's attempt to sign the root using DNSSEC. http://gnso.icann.org/mailing-lists/archives/ga-200709/msg02073.html regards joe baptista > > > The Kaminsky report created "urgency"; A frequent element of a scam is > to have such urgency that one can't stop to think about whether the > claims are legitimate or make sense. Professor Bruce Wedlock often > repeated "Always ask yourself 'Does this make sense?'" The Kaminsky > report, by the way, is entirely false regarding the discovery; many > people have already noted that DJB discovered this attack in the 1990s. > Of course, the attack could have been forgotten and 'rediscovered', but > that isn't the case, either. I found a design report for Unbound > (developed by Nominet, Verisign, NLnet Labs, EP.NET (Bill Manning)) > http://www.unbound.net/documentation/ietf67-design-02.pdf in which they > describe that "spoofed NS additionals confuse iterator". This paper was > discussed at IETF 67, in November 2006, so one can't even say that DJB > discovered the attack in the 90's but it was forgotten and rediscovered > by Kaminsky. Kaminsky just created a lot of "urgency", with the result > of scaring people into adopting DNSSEC. > > > [OT Note: BTW, for those still following the Bind Company (or Bind > Cartel as I like to call it), I have found evidence that Verisign is an > investor in Nominum, and that Paul Vixie is a founder of Nominum (well > known fact, but hard to find proof), and I have discovered that ISC and > Nominum share employees. I may put up a public wiki site for this, if > there's still interest. I also need someone in the SF bay area to check > out some things, too--if anyone is willing to help, contact me offlist > --thx] > > Back to DNSSEC: There are a number of problems with DNSSEC, besides the > one you just mentioned. There are a number of attacks on DNSSEC, > including replay attacks that still allow caches to be poisoned with bad > data. > > DNSSEC also enables new DDOS attacks, by merely forging DNSSEC requests > to DNSSEC domains. I haven't tested .gov yet, but one should be able to > get a fairly large response back. A small query (perhaps 64bytes) can > get an up to an 8KB response with DNSSEC. > > Deploying DNSSEC is a bad idea. > > I wonder how long before someone releases a tool to exploit DNSSEC > domains for a DDOS attack, like the "Rapid Enumeration Tool" (RET) > released by Nominet. The RET exploits open recursors to sureptitiously > enumerate NSEC records. > > "The Rapid Enumeration Tool (RET) is designed to use DNSSEC NSEC > records to enumerate quickly zone data whilst evading detection by > systems which might be designed specifically to identify zone > enumeration activity. It does this by using one or more open recursive > resolvers to forward queries to the authoritative name servers for the > zone. Each resolver is configured with its own 'personality', > specifying query rates, query failure/success ratio, proportions of > query types, query name decoration, etc. This allows the RET to feed > queries to each resolver, that are specifically tailored to match the > queries that a resolver might typically send to the authoritative name > server. Unlike other NSEC resource record 'walkers', the RET does not > explicitly query for NSEC RRs to walk the zone. Instead, it combines a > 'walker' approach with a dictionary attack (combined with a random name > generator for more awkward cases). This means that discernible > artifacts in the pattern of queries that arrive at the authoritative > servers should be minimised." -- from http://www.dnssec.net/software > > > > --Dean > > On Mon, 22 Sep 2008, Jason Frisvold wrote: > > > Hi all, > > > > I guess I've been meaning to join this list for some time, but since > > DJBDNS just seems to work, I haven't had a real need... However, that > > may change. It appears that the Federal Government has mandated a > > rollout of DNSSEC for all .gov domains. They're spinning this as a > > way to be "sure" that you get to the proper government site, but fail > > to mention that without valid resolvers on the user end, there is > > still zero security. > > > > Regardless, this may mean that DNSSEC is here to stay. It's still a > > bit early, though, and the apparent mandate for IPv6 hasn't proven to > > make it any more popular either. > > > > What is being done on the DJBDNS front, though? I see mention of a > > new crypto DNS library, DNSCurve, though it appears that there is no > > current release. Is this the answer to DNSSEC? Will this be > > "compatible" with DNSSEC, or will I eventually be forced to move to > > other resolvers? > > > > Thanks! > > > > > > -- > Av8 Internet Prepared to pay a premium for better service? > www.av8.net faster, more reliable, better service > 617 344 9000 > > > > -- Joe Baptista www.publicroot.org PublicRoot Consortium ---------------------------------------------------------------- The future of the Internet is Open, Transparent, Inclusive, Representative & Accountable to the Internet community @large. ---------------------------------------------------------------- Office: +1 (360) 526-6077 (extension 052) Fax: +1 (509) 479-0084