Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 12 Feb 2009, Paul Jarc wrote: > Dean Anderson <[email protected]> wrote: > > This appears to increase the vulnerability, particularly if the UDP > > ports can be predicted because they don't change as often. In that case, > > the attack is reduced to number of probable UDP ports * 64k packets to > > run though the QIDs. > > I'm not following you - what makes you think UDP ports won't change as > often? Before: 200 uncached queries, 200 udp ports consumed and 'returned to the Urn'. After patch: 200 uncached queries, perhaps 1 udp port consumed. With caching, Attacker makes one query that will hit its nameserver, records the port, predicts the likely next port, runs an attack on that +small n to account for a few unrelated queries. Merging queries results in less port use. > > An important point was that Kevin's formula for Birthday attack was > > wrong, as was their whole mathematical analysis. > > Are you talking about the analysis in > http://www.your.org/dnscache/djbdns.pdf, or something else? Can you > explain exactly where it goes wrong? Kaminsky's formula and the correct formula are in two messages I sent from DNSEXT. There's a little more in offlist discussion from October, where we talked about the mistakes he made; but the two messages I sent detail the pertinent facts. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000