Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Matthew Dempsky <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Fri, Feb 20, 2009 at 2:32 PM, Dean Anderson <[email protected]> wrote:
> Another scenario is they DOS attack the authority server, and cause
> either the single query or the single response to be lost, enabling a
> longer time on the attack.

This attack applies to unpatched dnscache too.  If you DOS the
authority server and cause any of the responses to be lost, then
dnscache's corresponding query ports are vulnerable to attack for a
longer period of time.  You understand that if unpatched dnscache
sends 200 query packets for the same name, that an attacker only has
to successfully forge a response packet to one of these queries for
his attack to succeed, right?

If you're going to continue bad mouthing Kevin Day and Jeff King, I
expect you to describe an attack that is more effective against
dnscache-with-qmerge than dnscache-without-qmerge.

Is there anyone on this list other than Dean that thinks his arguments
against Kevin's qmerge patch are at all credible?  If not, I'm going
to give up on replying to his emails until I see one with concrete
details of an attack against the patch.  I'm tired of repeatedly
asking him to specify one, and his lack of logical reasoning is too
infuriating for me to continue without good cause.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.