Re: djbdns/dnscache poisoning weakness

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
There is no improvement. It took 28 million packets to spoof DNScache
before Kaminsky, and I'm concerned it may take less than that now.  

But Kaminsky didn't discover ANYTHING technical.  There were no "new
facts" that he pointed out. All of these are OLD facts, that people
already knew for years prior; I've tracked down the sources that predate
Kaminsky. If Kaminsky had filed a patent, it would be invalidated by
prior art.

All Kaminsky "discovered" was how to hack the media, and get a lot of
people to take untried, untested, UNEXAMINED changes from someone in the
blackhat community. (The blackhat community generally publishes exploit
examples, not patches)  But hacking the media isn't a discovery, but a
social engineering con.  Kevin Mitnick is a smart guy too, but I'm not
going to let him near my critical systems, and I'm not going to take any
patches from him. I wouldn't want to use software from anyone who does.  
I'd certainly look at any example exploit code he writes, but Mitnick
might still be barred from doing that. Kaminsky didn't write any exploit
example, or didn't share it.

The changes to DNScache (SOA caching, query merging), after 8 months of
waiting for some "serious exploit", are at best performance
enhancements. The absence of these does not create exploitable
weaknesses. There is no serious exploit. It was all a scam. I'm sure the
blackhat community is thinking about the next such confidence scheme.

The only real security change in this whole thing was that BIND finally
took Bernstein's advice to use random ports. BIND was told about that
MANY years ago, and everyone else adopted it by 2006. But BIND
stubbornly refused, and for 2 years remained the only server not to use
random ports.  But it was Bernstein, not Kaminsky, who discovered this
weakness. And the business about spoofing nameservers in the authority
data was also known in 2006, before Kaminsky.  There is nothing
technical in this security scare to put Kaminsky's name on.

In fact, some of the "contributors" to the DNScache patches are known to
be Vixie/BIND Cartel folks. For example, Kaminsky cites David Ulevitch.  
Ulevitch, of OpenDNS, is tied to Vixie.  It might be the case that BIND
Cartel just wanted to smear DNScache with a "security bug" of its own,
or it might be the case that the BIND cartel staged this whole thing to
change BIND and get everyone to take the patches, giving all the credit
for the 'discovery' to Kaminsky without having to concede that Bernstein
discovered this problem and discovered the fix years ago. Perhaps it
doesn't matter. What matters is that Kaminsky didn't discover anything
about DNS on which to hang his name.

		--Dean




On Thu, 12 Feb 2009, Matthew Dempsky wrote:

> On Thu, Feb 12, 2009 at 2:26 PM, Dean Anderson <[email protected]> wrote:
> > Ah. The scam. "Lather, Rinse, Repeat, and success". There are lots of
> > algorithms to "lather rinse repeat and successfully break crypto.
> 
> Your critical reading skills are embarrassing.
> 
> "Repeat the scenario above" wasn't meaning "brute force until
> success," it was "here's how to improve the same attack, taking
> advantage of these new facts I've just pointed out."
> 
> 

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.