Re: djbdns/dnscache poisoning weakness
Kevin Day <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Okay, last shot at setting the record straight. If this doesn't do it, I'm keeping quiet unless the email is in the form of "If you do [xxxx], you can poison dnscache in 1000 messages." > > On Tue, 10 Feb 2009, Mark Johnson wrote: > >> Please explain how Jeff King's patches make it possible to poison >> dnscache in 1000 messages. > > That's easy. I never said "_Jeff King's_ patches make it possible to > poison dnscache in 1000 messages." I said that about the Day/Kaminsky > proposed changes for the same "vulnerabilities" they just quoted. This is why I think you're either confusing me with someone else, and/ or are looking at the wrong patches. 1) Dan Kaminksy and I have never worked together on anything. I have sent a grand total of maybe 10 emails to the guy in my life. I have talked to YOU more than him. I've followed his work, but we honestly have done nothing together. The extent of his involvement with the djbdns weaknesses I researched can be boiled down to: "Hey, Dan... I know you've been looking at DNS poisoning lately, can you look at this and see if I've missed anything?" "Looks like you've found something interesting, Kevin. See if you can exploit it, and I'll check your work." I have nothing against Dan, but it's incorrect to say that there could possibly be anything called "the Day/Kaminsky proposed changes." I don't believe there has been any overlap in anything the two of us have ever done. 2) The weaknesses in my paper, the suggested corrections in my paper, and Jeff King's patches are the same thing. Jeff was given my early write-up of what I'd been looking at, and came up with patches to correct them. As far as I'm aware, the earliest you could have possibly seen Jeff's patches was on February 9th, like everyone else. I don't know what you saw that had a weakness in the "breakable in 1000 tries" range, but you'd made that claim long before you ever saw Jeff's work. Jeff's patches are directly addressing the weaknesses in my paper. > "Vulnerabilities" that they never quite got around to analyzing > mathematically, or even showing that they can be exploited in > reasonable > time. I guess they decided not to try math again, after I found their > last math analysis incorrect. > 3) If you read the PDF I released yesterday, you'd see a pretty detailed example of exactly how to exploit this, as well as the data from 5 back-to-back test runs showing exactly how long it took. I'm not going to release a script-kiddie proof of concept, but everything you need is there to try it yourself. 4) The math for this has been done, and was actually presented at the Internet Society's NDSS Symposium today. Tuesday, February 10, 2009 10:30 - 12:00 Recursive DNS Architectures and Vulnerability Implications David Dagon, Manos Antonakakis, Xiapu Luo, Christopher P. Lee and Wenke Lee, Georgia Institute of Technology; Kevin Day, kevinday.com We explore how different DNS resolver architectures affect the risk of DNS poisoning. To measure the threat found in existing and recent DNS attacks, we create a comprehensive DNS poisoning model, and demonstrate its sensitivity compared to previous work. We further catalog major architectural choices DNS implementers can make in query management. We note real-world instances where these choices have weakened the security of resolvers. Our study points to the need for secure DNS replacements. I'll find out when/where the paper is viewable to those not at the conference. (I couldn't attend, either.) > > I have provided an argument, which you're just to lazy to look up. > Though there may be some important offlist messages that need to be > reported, yet. This is in stark contrast to Day and Kaminsky, who made > unsubstantiated claims in July 2008, that they are just now posting > publicly, some __8_months__ later. I deserve the same 8 months to > review, update or merely _RE-POST_ my arguments. > > [citation needed] I've also tried looking this up, and failed to find anything relevant. You emailed Dan and I with a vague understanding of the issues, but missing several key points. You did some math that I honestly couldn't figure out, and decided that the problem you think I was going to disclose was incorrect. That's got no bearing on what was released yesterday. > Gee, I notice that this is the same sort of thing that the BIND Cartel > says about me. Usually before they try to silence me, while hurling > insults and epithets. So, now they accuse me of 'not being interested > in civil rational discussion'. Ah, the irony of it. > Dean... I *tried so desperately hard* to have a rational discussion with you. I offered to sit on the phone with you, until one of us could understand the other's viewpoint. I gave you access to materials 2 weeks before anyone else, because I honestly respected your input and wanted to avoid a situation like this. I was completely willing to pull the paper/patches if you'd come to me with any legitimate concerns. You didn't have time to read/email me then, but found time to post publicly a few hours after the deadline. I honestly don't care what you think my motives are anymore. I'm not a security researcher. I'm not in this for publicity. I'm just a djbdns user like you, trying to keep using a package that hasn't been updated in around 7 years. If you can plainly identify any weakness or mistake in the paper or patches, not what you think you read months ago, I'm all ears. Otherwise, I'm done. Rather than everyone discussing DNS security, we're bickering over who said what and when. -- Kevin