Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

David Nicol <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
I'm going to jump in again because I like the popcorn popper metaphor.

On Wed, Feb 18, 2009 at 12:45 AM, Dean Anderson <[email protected]> wrote:

> You are mixing apples and oranges. The first scenario, unmodified
> DNScache, requires a birthday attack which we can analyze. The second
> scenario Kaminksy/Day/King DNScache changes, depends on changes
> suggested by a blackhat hacker and lowers the randomness of the port
> usage.  Imagine a popcorn popper that runs a lot slower. Slow enough to
> follow.

calling each other names is called an "ad hominem fallacy" and is
out-of-bounds in constructive collaborative search for truth.

About the popcorn popper (yum, popcorn!  Suddenly typing sounds like
popping popcorn) metaphor: if the birthday attack is equivalent to
placing a little basketball hoop inside the big popcorn popper and
winning when a popcorn flies through it, someone who wants popcorn to
fly through the hoop wants the popper to run fill tilt rather than
slower.

> Also, Kaminsky (and presumably Day) are reasonably skilled programmers,
> and the changes aren't very big; and DNScache isn't very complicated.
> Getting King to implement the changes and dropping Kaminsky and Day's
> involvement is also kind of like laundering the blackhat taint using
> Jeff King's non-blackhat reputation.

This whole conspiracy theory thing is fascinating, regardless of its
truth weight.  The dark side of genius.

> My solution keeps the randomness high (keeps the popcorn popper going
> full steam), and avoids the poison altogether by falling back to TCP
> when an attack is detected. Falling back to TCP when an attack is
> detected isn't nearly as much DNS TCP traffic as using TCP all the time.
> Are you opposed to this solution? If so, why?

A moderate conservative here is opposed to /any change/ without a
demonstrable exploit, so the cruder tools of benchmarking can be used
in preference to the faith-based tools of analysis.  He hears
Anderson's fears about "blackhats" and notes that said alleged
blackhats call Anderson a loony, which actually supports Anderson's
claim against them, then Anderson proposes a change too, also based on
analysis rather than benchmarking, which supports their claim against
him.


>> You keep alluding to your knowledge of cryptography.  You understand
>> security reduction proofs, right?
>
> I see a lot of net people talking with this term. I see no scientific
> papers that use it.  It seems to be a big, scientific-sounding word
> meaning 'a chain is no stronger than its weakest link'. So, yes, I guess
> I know about that.

I'll second this -- what's a good reference for what is a security
reduction proof?
http://en.wikipedia.org/wiki/Provable_security seems like a nice
introduction, my takeaway from reading the article was that "provable
security" is concerned with making "given A, therefore B" kinds of
statements in a formal way, and that the literature of that field
calls their proven lemmas "reductions".  My wife the chef calls broth
with most of the water boiled out of it a reduction.  Go figure.


> In the case of my proposal, the easiest attack should still be the
> birthday attack; I don't alter anything that might affect entropy.  And
> the Birthday attack is made harder to carry out in practice by detecting
> it and falling back to invulnerable TCP, without the burden of using TCP
> all the time. Best of all possible worlds.

Dean's proposal can be summarized as "prefer TCP during heuristically
identified attacks" for those without photographic memories.  Oh, he
said that, above.  Cool, my memory works too!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.