Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 18 Feb 2009, Simon Casady wrote: > Dean Anderson said: ( I think it was Dean) > > "The rate of consumption of ports is substantially less. The 'popcorn > popper pops slower'. Usually this is a bad thing." > > I disagree, this is a good thing. The fewer queries to match the > smaller the chance of success. Always. You are refering to the birthday attack, while I am refering to port entropy. Apples and oranges. Your claim is true regarding the birthday attack exclusively. Kaminksy indeed makes the birthday attack harder, but introduces a new attack on the entropy of ports in doing so. The birthday attack (using all 64510 ports and 65536 QIDs) on a system with one port quite hard, billions of packets. But if that port is known to be bound to UDP 53, then the brute force attack on single known port requires only 65536 packets, quite easy. This is the flaw in your reasoning, too. Because the randomness of the port isn't perfect, the attack may be able to predict the port, and thereby reduce the effort required. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000