Re: Potentially Predatory Pre-Announcement of Possible Vaporware (zinq-djbdns-0.01)

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Fri, 14 Nov 2008, Daryl Tester wrote:

> > So, DNSSEC support would be a "Good Thing" to have.
> 
> This has been thrashed out on the list before -
> 
> <http://marc.info/?l=djbdns&w=2&r=1&s=dnssec&q=b>

DNSSEC support is sufficiently handled with EDNSO. There is no need to 
have DJBDNS try to comply with the rest of DNSSEC, since it can't be 
secure from wrong answers anyway, and just introduces a crypto overload 
attack into DJBDNS.

> I think we're still outstanding a tinydns "exploit" as well.  Intriguing
> innuendo.

Yes. I've heard nothing more, either, about the tinydns "exploit". It to
me seems the "fix" was the actual exploit. I've been meaning to anylyze
the BIND patches provided by Dan Kaminsky for the combined birthday
attacks I noticed in his proposal for TinyDNS changes.  I have to write
a response to NTIA on DNSSEC first.  I have found a number of other
interesting facts about Kaminsky, though that I'll report briefly:

In January 2006, Kaminsky announced he had found 580,000 open recursors
at a hacker conference called Schmoocon. Its unclear how all this
scanning was done without notice or complaint. Coicidentally, the first
DNS reflection attack is reported to have taken place in October 2005 in
a paper by Professor Vaughn of Baylor University and Gadi Evron released
in March 2006, which I just recently discovered.  They write:

  "Never-the-less, for the first 28 servers participating in
  this attack only 14 currently respond as supporting
  recursion. Again this is consistent with the attacker.s not
  fully gathering intelligence about the exploited servers
  prior to carrying out this attack."

So, half of the servers participating in the reflection attack weren't
open recursors. (?!?)  The authors attribute this to an error on the
attacker's part, which is preposterous: as if the attacker made an error
by exploiting closed recursors.

Curiously, this summer, when the report of the DNS cache poisoning
leaked out, Kaminsky writes that everyone must switch to OpenDNS "RIGHT
NOW".  OpenDNS operates open recursors.

I've just filed an appeal against the approval of
draft-ietf-dnsop-reflectors-are-evil with the IESG.

FYI, OpenDNS (www.opendns.com)  uses its open recursors to protect users
by denying DNS response to phishing sites, and collects information
about who's looking at what, which is probably useful for market
research and such.

FYI, there is an article in the Decmeber issue of MIT's Technology
Review about the DNS cache poisoning "exploit". This article describes
the over-the-top dramatic discussion by Vixie and Kaminsky, and the
skillful manipulation of the media, and the "Media Hack". So I think the
media is starting to come to grips with the fact there was nothing to
the "discovery", except a well known bug in BIND and some other servers,
which we all know that Dr. Bernstein discovered and fixed a long time
ago and was abused and censored by the BIND Cartel.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.