Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Jeff King <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Feb 20, 2009 at 05:24:24PM -0500, Dean Anderson wrote: > > > You collaborate with a known blackhat, Kaminsky. That makes you a > > > blackhat, too. (Media3 v. MAPS) That is a fact. > > > > Am I blackhat, too, then, since I collaborated with Kevin by making the > > patches[1]? I can't wait to reap the ill-gotten rewards of my life of > > crime. > > I think that all depends on what you do, I think. I can see that it I think you missed my point: if collaboration with Kaminsky makes Day a blackhat, then wouldn't collaboration with Day make me a blackhat? In other words, how can I (or anyone) possibly "launder the blackhat taint", if doing so makes me a blackhat? > > So do I still get to launder the blackhat taint away? > No. You don't. OK, well at least that is logically consistent. > I have a legitimate analysis of the problem; you have seen it; but you > STILL (if above is any indication) can't even repeat it back to me > accurately. Until you can show that you understand my analysis, or some > analysis, I can't really have rational discussion with you. Well, I certainly agree that it doesn't seem like we're having rational discussion; I am having a very hard time understanding the attack you claim exists. If it were just me, I might think I had a reading comprehension problem. But given the other responses, maybe you are not being clear enough? Paul was nice enough to post an attack scenario based on some of your comments; I have just replied with my own analysis which, unless there is an error, shows that it is not a problem. > Until you can accept that character matters, I can't trust you. I'm not asking you to trust me. I am asking you to look at the patches I wrote and decide whether you want to trust _them_ or not[1]. Patches do not have character. -Peff [1]: Actually, I don't even really care whether you trust the patches, or whether you install them on your system, or whether you recommend that other people install them. What I do care about is whether there is a practical attack that works better against qmerge-patched dnscache than it does against stock dnscache. You seemed to indicate that you know of one, which is interesting to me (and presumably to others on the list).