Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
		--Dean

On Wed, 18 Feb 2009, Jeff King wrote:

> On Wed, Feb 18, 2009 at 02:14:58PM -0500, Dean Anderson wrote:
> 
> > > Second... "blackhat"? I have never done anything in my life that could  
> > > be categorized as "blackhat" material. 
> > 
> > You collaborate with a known blackhat, Kaminsky. That makes you a
> > blackhat, too.  (Media3 v. MAPS) That is a fact. 
> 
> Am I blackhat, too, then, since I collaborated with Kevin by making the
> patches[1]? I can't wait to reap the ill-gotten rewards of my life of
> crime.

I think that all depends on what you do, I think.  I can see that it
might be that you were duped and fooled along with many others in this
event. But other than helping write the code, I can't see anything else
to criticize you for.  But, possibly you've done this before, or will
again.  Things add up; we have a word for that: reputation.

> But wait, earlier you said:
> 
> > Also, Kaminsky (and presumably Day) are reasonably skilled
> > programmers, and the changes aren't very big; and DNScache isn't very
> > complicated.  Getting King to implement the changes and dropping
> > Kaminsky and Day's involvement is also kind of like laundering the
> > blackhat taint using Jeff King's non-blackhat reputation.
> 
> So do I still get to launder the blackhat taint away?

No. You don't.

> My point isn't that I think your conspiracy theories are silly (which I
> do). It is that name-calling and second-guessing motives doesn't change 
> one whit the content of the patches. 

Yes, actually it does.  People concerned about security don't take
source code from dubious sources.

> It doesn't change whether there is a birthday attack against dnscache,
> nor what probabilities an attacker can expect (though obviously the
> risk posed by that probability is up to individual dnscache sites to
> determine). It doesn't change how the patches affect that probability.
> And it doesn't change whether or not there is a different attack that
> is made easier by the patches.
> 
> So either you have some legitimate analysis which shows a problem with
> the patches (which I have yet to see), or you don't.

I have a legitimate analysis of the problem; you have seen it;  but you
STILL (if above is any indication) can't even repeat it back to me
accurately.  Until you can show that you understand my analysis, or some
analysis, I can't really have rational discussion with you.

Until you can accept that character matters, I can't trust you.


		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.