Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
David Nicol <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
I'm going to jump in again because I like the popcorn popper metaphor. On Wed, Feb 18, 2009 at 12:45 AM, Dean Anderson <[email protected]> wrote: > You are mixing apples and oranges. The first scenario, unmodified > DNScache, requires a birthday attack which we can analyze. The second > scenario Kaminksy/Day/King DNScache changes, depends on changes > suggested by a blackhat hacker and lowers the randomness of the port > usage. Imagine a popcorn popper that runs a lot slower. Slow enough to > follow. calling each other names is called an "ad hominem fallacy" and is out-of-bounds in constructive collaborative search for truth. About the popcorn popper (yum, popcorn! Suddenly typing sounds like popping popcorn) metaphor: if the birthday attack is equivalent to placing a little basketball hoop inside the big popcorn popper and winning when a popcorn flies through it, someone who wants popcorn to fly through the hoop wants the popper to run fill tilt rather than slower. > Also, Kaminsky (and presumably Day) are reasonably skilled programmers, > and the changes aren't very big; and DNScache isn't very complicated. > Getting King to implement the changes and dropping Kaminsky and Day's > involvement is also kind of like laundering the blackhat taint using > Jeff King's non-blackhat reputation. This whole conspiracy theory thing is fascinating, regardless of its truth weight. The dark side of genius. > My solution keeps the randomness high (keeps the popcorn popper going > full steam), and avoids the poison altogether by falling back to TCP > when an attack is detected. Falling back to TCP when an attack is > detected isn't nearly as much DNS TCP traffic as using TCP all the time. > Are you opposed to this solution? If so, why? A moderate conservative here is opposed to /any change/ without a demonstrable exploit, so the cruder tools of benchmarking can be used in preference to the faith-based tools of analysis. He hears Anderson's fears about "blackhats" and notes that said alleged blackhats call Anderson a loony, which actually supports Anderson's claim against them, then Anderson proposes a change too, also based on analysis rather than benchmarking, which supports their claim against him. >> You keep alluding to your knowledge of cryptography. You understand >> security reduction proofs, right? > > I see a lot of net people talking with this term. I see no scientific > papers that use it. It seems to be a big, scientific-sounding word > meaning 'a chain is no stronger than its weakest link'. So, yes, I guess > I know about that. I'll second this -- what's a good reference for what is a security reduction proof? http://en.wikipedia.org/wiki/Provable_security seems like a nice introduction, my takeaway from reading the article was that "provable security" is concerned with making "given A, therefore B" kinds of statements in a formal way, and that the literature of that field calls their proven lemmas "reductions". My wife the chef calls broth with most of the water boiled out of it a reduction. Go figure. > In the case of my proposal, the easiest attack should still be the > birthday attack; I don't alter anything that might affect entropy. And > the Birthday attack is made harder to carry out in practice by detecting > it and falling back to invulnerable TCP, without the burden of using TCP > all the time. Best of all possible worlds. Dean's proposal can be summarized as "prefer TCP during heuristically identified attacks" for those without photographic memories. Oh, he said that, above. Cool, my memory works too!