Re: djbdns/dnscache poisoning weakness
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
There is no improvement. It took 28 million packets to spoof DNScache before Kaminsky, and I'm concerned it may take less than that now. But Kaminsky didn't discover ANYTHING technical. There were no "new facts" that he pointed out. All of these are OLD facts, that people already knew for years prior; I've tracked down the sources that predate Kaminsky. If Kaminsky had filed a patent, it would be invalidated by prior art. All Kaminsky "discovered" was how to hack the media, and get a lot of people to take untried, untested, UNEXAMINED changes from someone in the blackhat community. (The blackhat community generally publishes exploit examples, not patches) But hacking the media isn't a discovery, but a social engineering con. Kevin Mitnick is a smart guy too, but I'm not going to let him near my critical systems, and I'm not going to take any patches from him. I wouldn't want to use software from anyone who does. I'd certainly look at any example exploit code he writes, but Mitnick might still be barred from doing that. Kaminsky didn't write any exploit example, or didn't share it. The changes to DNScache (SOA caching, query merging), after 8 months of waiting for some "serious exploit", are at best performance enhancements. The absence of these does not create exploitable weaknesses. There is no serious exploit. It was all a scam. I'm sure the blackhat community is thinking about the next such confidence scheme. The only real security change in this whole thing was that BIND finally took Bernstein's advice to use random ports. BIND was told about that MANY years ago, and everyone else adopted it by 2006. But BIND stubbornly refused, and for 2 years remained the only server not to use random ports. But it was Bernstein, not Kaminsky, who discovered this weakness. And the business about spoofing nameservers in the authority data was also known in 2006, before Kaminsky. There is nothing technical in this security scare to put Kaminsky's name on. In fact, some of the "contributors" to the DNScache patches are known to be Vixie/BIND Cartel folks. For example, Kaminsky cites David Ulevitch. Ulevitch, of OpenDNS, is tied to Vixie. It might be the case that BIND Cartel just wanted to smear DNScache with a "security bug" of its own, or it might be the case that the BIND cartel staged this whole thing to change BIND and get everyone to take the patches, giving all the credit for the 'discovery' to Kaminsky without having to concede that Bernstein discovered this problem and discovered the fix years ago. Perhaps it doesn't matter. What matters is that Kaminsky didn't discover anything about DNS on which to hang his name. --Dean On Thu, 12 Feb 2009, Matthew Dempsky wrote: > On Thu, Feb 12, 2009 at 2:26 PM, Dean Anderson <[email protected]> wrote: > > Ah. The scam. "Lather, Rinse, Repeat, and success". There are lots of > > algorithms to "lather rinse repeat and successfully break crypto. > > Your critical reading skills are embarrassing. > > "Repeat the scenario above" wasn't meaning "brute force until > success," it was "here's how to improve the same attack, taking > advantage of these new facts I've just pointed out." > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000