Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Matthew Dempsky <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Feb 20, 2009 at 2:32 PM, Dean Anderson <[email protected]> wrote: > Another scenario is they DOS attack the authority server, and cause > either the single query or the single response to be lost, enabling a > longer time on the attack. This attack applies to unpatched dnscache too. If you DOS the authority server and cause any of the responses to be lost, then dnscache's corresponding query ports are vulnerable to attack for a longer period of time. You understand that if unpatched dnscache sends 200 query packets for the same name, that an attacker only has to successfully forge a response packet to one of these queries for his attack to succeed, right? If you're going to continue bad mouthing Kevin Day and Jeff King, I expect you to describe an attack that is more effective against dnscache-with-qmerge than dnscache-without-qmerge. Is there anyone on this list other than Dean that thinks his arguments against Kevin's qmerge patch are at all credible? If not, I'm going to give up on replying to his emails until I see one with concrete details of an attack against the patch. I'm tired of repeatedly asking him to specify one, and his lack of logical reasoning is too infuriating for me to continue without good cause.