Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Wed, 18 Feb 2009, Jeff King wrote:


> Here's why your strawman doesn't apply. Matthew indicated that one
> _particular_ class of changes (e.g., the one in the qmerge patches) has
> this property. 

No class changes inherently has that property.  The point of contention
is that the qmerge patches alter the entropy on port numbers and alter
the success on other attacks.  Matthew says the qmerge changes don't
alter anything else. He's wrong.

> No, the math is the entire argument. Either the patches impact the
> birthday attack, or they don't. Either they introduce a new attack, or
> they don't.

We agree.  The patches make the birthday attack harder. They make other 
attacks easier.

> > I am quite taken aback by the notion that character doesn't matter. I
> > see that a lot in some quarters---it is the common assertion of the
> > dishonest---but I didn't expect it here.  It is said that character is
> > to people what carbon is to steel.  One must first _have_ good character
> > and good judgement to be trusted for their good character and judgement.
> > Who one associates with is part of their trustworthiness and character.
> > I won't trust people who naively but knowingly associate with
> > disreputable people.
> 
> The character and reputation of the source of a message are a useful
> guess when you are too lazy or too short on time to look at the
> facts of the message (or when you refuse to open the PDF containing the
> message). But they are not a valid argument against the _facts_ of the
> message. Bad people saying true things does not make them untrue, nor
> do good people saying untrue things make them true.

Bad people are indeed saying untrue things.  Almost everything they have
said has been false. Yet for some reason, you want 1% of what they said,
the patches, to be true.  Let me make this clear:

   It doesn't matter whether the patches are true (they aren't, but it
   doesn't matter).  Due to reputation, they can't be accepted.

> > But I am concerned because they have already proposed a change that
> > would create a serious flaw by reusing QIDs, and every claim of
> 
> How are QIDs reused? Each outgoing (i.e., spoofable) packet should get a
> single unique QID. If it doesn't, then there is a bug in the patch, and
> I would be happy for you to point it out.

The qmerge patches don't reuse QIDs. The first proposal for changes sent
to me by Kaminsky/Day, however, did do that. I saw it, did the math, and
objected. They changed their proposal and patches very slightly.

		--Dean


-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.