Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 18 Feb 2009, Matthew Dempsky wrote: > On Wed, Feb 18, 2009 at 1:12 PM, Dean Anderson <[email protected]> wrote: > > Yes, I do know that qmerge doesn't make THAT change. My example was > > to demonstrate that changes affect the attacks that are possible. > > That's a straw man. No one suggested that changes never affect attack > success probabilities. You said: > So you understand that if an attacker can carry out an attack against > dnscache with a single outstanding UDP query, then he can apply the > same technique when dnscache has 200 outstanding UDP queries and have > the same (or better) chance of success, right? I.e., you understand > that any attack that an attacker can carry out with the qmerge patches > applied, he can still carry out without it applied, right? To which I said: No, the above isn't true in any non-trivial sense. One can obviously attempt any attack at any time (the trivial sense). But the chance of success of any given attack depends on the changes made to DNScache. For example, if you change it so to bind the port to 53, the chances of a brute force attack change to 1 in 65536. Doh. It appears that I gave the correct analysis. > What I said, and continue to stand by, is that for any forgery attack > against djbdns 1.05 patched with Kevin Day's qmerge patch, there > exists another forgery attack against stock djbdns 1.05 with > comparable or better chance of success. You have not demonstrated this. You can "stand by" anything. I don't think you understand the math behind the birthday attack, and so you can't really have an understanding of the attacks against stock DJBDNS. I don't think you appreciate the potential for new attacks that can be added by making changes. This potential is why one doesn't ever accept changes from blackhats. They could easily fool many people about the effects of their changes. These are questions of trust for source trees. Your naivete on that point is astonishing. > You refute this statement, but have so far failed to give any > arguments discrediting it. Untrue. You have merely failed to understand my arguments. You have not discredited any of my arguments. > Instead you wave your arms about ridiculous changes like disabling > dnscache's random number generator. That's your opinion of my arguments, and it seems to be you who is waving arms. You haven't shown my math to be wrong. In fact, I _have_ provided sufficient mathematical argument to show that entropy of port numbers may be affected by Kaminsky's changes, and is unaffected by my changes. You just don't follow the math, I'm not sure that you follow any of the math. But math is only half the argument against Kaminsky/Day/Kings changes. Trust is the other part, and the changes originate from an untrustworthy source, a known blackhat, who has been discredited on all of the claims of discovering a flaw in DNS. I think you have been incredibly gullible; taken in by a blackhat in the most incredibly naive way. Honest people should deal with blackhats the same way that the FBI deals with informants: you take their information, but you never help them accommplish their plans. Jeff King has gullibly helped them launder their bad reputations by putting his good name on their plans. That was poor judgement on his part. And you are quite naive to be taken in by trusting their patches. That also seems like poor judgement to me, but I can't make your decisions for either of you. I am quite taken aback by the notion that character doesn't matter. I see that a lot in some quarters---it is the common assertion of the dishonest---but I didn't expect it here. It is said that character is to people what carbon is to steel. One must first _have_ good character and good judgement to be trusted for their good character and judgement. Who one associates with is part of their trustworthiness and character. I won't trust people who naively but knowingly associate with disreputable people. Anyway, I can't change your opinion by rational argument---you are apparently convinced in your beliefs---and you don't understand the math, so rational argument is a lost effort. But I am concerned because they have already proposed a change that would create a serious flaw by reusing QIDs, and every claim of discovery has been discredited. They have conducted a tremendous media scam. There is no way anyone who is interested in a trustworthy codebase would ever accept source code changes from a blackhat. I've already said what I plan to do. There seems no point in further argument. We all have our minds made up. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000