Re: Potentially Predatory Pre-Announcement of Possible Vaporware (zinq-djbdns-0.01)
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 14 Nov 2008, Daryl Tester wrote: > > So, DNSSEC support would be a "Good Thing" to have. > > This has been thrashed out on the list before - > > <http://marc.info/?l=djbdns&w=2&r=1&s=dnssec&q=b> DNSSEC support is sufficiently handled with EDNSO. There is no need to have DJBDNS try to comply with the rest of DNSSEC, since it can't be secure from wrong answers anyway, and just introduces a crypto overload attack into DJBDNS. > I think we're still outstanding a tinydns "exploit" as well. Intriguing > innuendo. Yes. I've heard nothing more, either, about the tinydns "exploit". It to me seems the "fix" was the actual exploit. I've been meaning to anylyze the BIND patches provided by Dan Kaminsky for the combined birthday attacks I noticed in his proposal for TinyDNS changes. I have to write a response to NTIA on DNSSEC first. I have found a number of other interesting facts about Kaminsky, though that I'll report briefly: In January 2006, Kaminsky announced he had found 580,000 open recursors at a hacker conference called Schmoocon. Its unclear how all this scanning was done without notice or complaint. Coicidentally, the first DNS reflection attack is reported to have taken place in October 2005 in a paper by Professor Vaughn of Baylor University and Gadi Evron released in March 2006, which I just recently discovered. They write: "Never-the-less, for the first 28 servers participating in this attack only 14 currently respond as supporting recursion. Again this is consistent with the attacker.s not fully gathering intelligence about the exploited servers prior to carrying out this attack." So, half of the servers participating in the reflection attack weren't open recursors. (?!?) The authors attribute this to an error on the attacker's part, which is preposterous: as if the attacker made an error by exploiting closed recursors. Curiously, this summer, when the report of the DNS cache poisoning leaked out, Kaminsky writes that everyone must switch to OpenDNS "RIGHT NOW". OpenDNS operates open recursors. I've just filed an appeal against the approval of draft-ietf-dnsop-reflectors-are-evil with the IESG. FYI, OpenDNS (www.opendns.com) uses its open recursors to protect users by denying DNS response to phishing sites, and collects information about who's looking at what, which is probably useful for market research and such. FYI, there is an article in the Decmeber issue of MIT's Technology Review about the DNS cache poisoning "exploit". This article describes the over-the-top dramatic discussion by Vixie and Kaminsky, and the skillful manipulation of the media, and the "Media Hack". So I think the media is starting to come to grips with the fact there was nothing to the "discovery", except a well known bug in BIND and some other servers, which we all know that Dr. Bernstein discovered and fixed a long time ago and was abused and censored by the BIND Cartel. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000