Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Wed, 18 Feb 2009, Matthew Dempsky wrote:

> On Wed, Feb 18, 2009 at 1:12 PM, Dean Anderson <[email protected]> wrote:
> > Yes, I do know that qmerge doesn't make THAT change. My example was
> > to demonstrate that changes affect the attacks that are possible.
> 
> That's a straw man.  No one suggested that changes never affect attack
> success probabilities.

You said:

> So you understand that if an attacker can carry out an attack against
> dnscache with a single outstanding UDP query, then he can apply the
> same technique when dnscache has 200 outstanding UDP queries and have
> the same (or better) chance of success, right?  I.e., you understand
> that any attack that an attacker can carry out with the qmerge patches
> applied, he can still carry out without it applied, right?

To which I said:

  No, the above isn't true in any non-trivial sense.  One can obviously
  attempt any attack at any time (the trivial sense).  But the chance of
  success of any given attack depends on the changes made to DNScache.
  For example, if you change it so to bind the port to 53, the chances 
  of a brute force attack change to 1 in 65536. Doh.

It appears that I gave the correct analysis.

> What I said, and continue to stand by, is that for any forgery attack
> against djbdns 1.05 patched with Kevin Day's qmerge patch, there
> exists another forgery attack against stock djbdns 1.05 with
> comparable or better chance of success.

You have not demonstrated this. You can "stand by" anything.  I don't
think you understand the math behind the birthday attack, and so you
can't really have an understanding of the attacks against stock DJBDNS.  
I don't think you appreciate the potential for new attacks that can be
added by making changes.  This potential is why one doesn't ever accept
changes from blackhats. They could easily fool many people about the
effects of their changes. These are questions of trust for source trees.  
Your naivete on that point is astonishing.

> You refute this statement, but have so far failed to give any
> arguments discrediting it.

Untrue. You have merely failed to understand my arguments. You have not
discredited any of my arguments.

> Instead you wave your arms about ridiculous changes like disabling
> dnscache's random number generator.

That's your opinion of my arguments, and it seems to be you who is
waving arms.  You haven't shown my math to be wrong. In fact, I _have_
provided sufficient mathematical argument to show that entropy of port
numbers may be affected by Kaminsky's changes, and is unaffected by my
changes.  You just don't follow the math, I'm not sure that you follow
any of the math.

But math is only half the argument against Kaminsky/Day/Kings changes.  
Trust is the other part, and the changes originate from an untrustworthy
source, a known blackhat, who has been discredited on all of the claims
of discovering a flaw in DNS.

I think you have been incredibly gullible; taken in by a blackhat in the
most incredibly naive way.  Honest people should deal with blackhats the
same way that the FBI deals with informants: you take their information,
but you never help them accommplish their plans. Jeff King has gullibly
helped them launder their bad reputations by putting his good name on
their plans. That was poor judgement on his part.  And you are quite
naive to be taken in by trusting their patches. That also seems like
poor judgement to me, but I can't make your decisions for either of you.

I am quite taken aback by the notion that character doesn't matter. I
see that a lot in some quarters---it is the common assertion of the
dishonest---but I didn't expect it here.  It is said that character is
to people what carbon is to steel.  One must first _have_ good character
and good judgement to be trusted for their good character and judgement.
Who one associates with is part of their trustworthiness and character.
I won't trust people who naively but knowingly associate with
disreputable people.

Anyway, I can't change your opinion by rational argument---you are
apparently convinced in your beliefs---and you don't understand the
math, so rational argument is a lost effort.

But I am concerned because they have already proposed a change that
would create a serious flaw by reusing QIDs, and every claim of
discovery has been discredited. They have conducted a tremendous media
scam.  There is no way anyone who is interested in a trustworthy
codebase would ever accept source code changes from a blackhat.

I've already said what I plan to do.  There seems no point in further
argument. We all have our minds made up.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.