Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
I'm going to try again.

On Fri, 13 Feb 2009, Matthew Dempsky wrote:

> On Fri, Feb 13, 2009 at 12:54 AM, Dean Anderson <[email protected]> wrote:
> > You simply didn't follow the math of a birthday attack with 200 ports
> > out of 65k.
> 
> Sorry, I followed the math fine.

If you say so.

> > Each port of 200 used has a unique QID. The attacker has to
> > get BOTH the port AND the QID correct.
> 
> Right.  But in this scenario, a single forged response packet has
> potentially 200 chances of success (because it might match any
> port/qid pair).  With the qmerge patches applied, a single forged
> response packet can never match more than one outstanding query.

You are mixing apples and oranges. The first scenario, unmodified
DNScache, requires a birthday attack which we can analyze. The second
scenario Kaminksy/Day/King DNScache changes, depends on changes
suggested by a blackhat hacker and lowers the randomness of the port
usage.  Imagine a popcorn popper that runs a lot slower. Slow enough to
follow.

Also, Kaminsky (and presumably Day) are reasonably skilled programmers,
and the changes aren't very big; and DNScache isn't very complicated.
Getting King to implement the changes and dropping Kaminsky and Day's
involvement is also kind of like laundering the blackhat taint using
Jeff King's non-blackhat reputation.

My solution keeps the randomness high (keeps the popcorn popper going
full steam), and avoids the poison altogether by falling back to TCP
when an attack is detected. Falling back to TCP when an attack is
detected isn't nearly as much DNS TCP traffic as using TCP all the time.  
Are you opposed to this solution? If so, why?


> > With exactly one port, that port might be
> > predictable, or they might be able to find it easilly with a quick scan
> > for open/closed ports.
> 
> You keep alluding to your knowledge of cryptography.  You understand
> security reduction proofs, right?

I see a lot of net people talking with this term. I see no scientific
papers that use it.  It seems to be a big, scientific-sounding word
meaning 'a chain is no stronger than its weakest link'. So, yes, I guess
I know about that.

> So you understand that if an attacker can carry out an attack against
> dnscache with a single outstanding UDP query, then he can apply the
> same technique when dnscache has 200 outstanding UDP queries and have
> the same (or better) chance of success, right?  I.e., you understand
> that any attack that an attacker can carry out with the qmerge patches
> applied, he can still carry out without it applied, right?

No, the above isn't true in any non-trivial sense.  One can obviously
attempt any attack at any time (the trivial sense).  But the chance of
success of any given attack depends on the changes made to DNScache.  
For example, if you change it so to bind the port to 53, the chances of
a brute force attack change to 1 in 65536. Doh.

So we need to consider out three cases. In the unmodified case, the
easiest attack is the birthday attack.  The math is well understood.  
In the Kaminsky/Day/King modified case, there might be an easier attack
based on the lowered randomness of port numbers.

In the case of my proposal, the easiest attack should still be the
birthday attack; I don't alter anything that might affect entropy.  And
the Birthday attack is made harder to carry out in practice by detecting
it and falling back to invulnerable TCP, without the burden of using TCP
all the time. Best of all possible worlds.


BTW, I don't pretend to be a real crypto expert. Some elaboration is
needed here. Previously, when I've said I'm not an expert on a subject,
idiots and the ignorant get very excited.  When someone says they aren't
a professional expert in a subject, it doesn't mean they aren't
knowledgeable. It means that I'm not on the same league as say DJB, or
probably any of the authors of the crypto papers I read. But I do know a
fair amount of math, and I do read as widely as I can, and I have a
nearly photographic memory. Today, for example, I remembered the UPS
tracking number from the slip, after I left the slip home. I've usually
been right when reporting what I read, and I try always to give sources
of important facts.  I also apply what I read. For example, some years
ago I discovered that Information Theory shows that spam cannot be
stopped by any technical means, but is always a whackamole operation
(I'll spare you the details). Usually these abilities are regarded as an
asset, but sometimes they have been the great chagrin of, e.g the BIND
Cartel, particularly those who are trying to pull something that can be
spotted as BS if one merely remembers some facts.

		--Dean
-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.