Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Jeff King <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Fri, Feb 20, 2009 at 05:24:24PM -0500, Dean Anderson wrote:

> > > You collaborate with a known blackhat, Kaminsky. That makes you a
> > > blackhat, too.  (Media3 v. MAPS) That is a fact. 
> > 
> > Am I blackhat, too, then, since I collaborated with Kevin by making the
> > patches[1]? I can't wait to reap the ill-gotten rewards of my life of
> > crime.
> 
> I think that all depends on what you do, I think.  I can see that it

I think you missed my point: if collaboration with Kaminsky makes Day a
blackhat, then wouldn't collaboration with Day make me a blackhat? In
other words, how can I (or anyone) possibly "launder the blackhat
taint", if doing so makes me a blackhat?

> > So do I still get to launder the blackhat taint away?
> No. You don't.

OK, well at least that is logically consistent.

> I have a legitimate analysis of the problem; you have seen it;  but you
> STILL (if above is any indication) can't even repeat it back to me
> accurately.  Until you can show that you understand my analysis, or some
> analysis, I can't really have rational discussion with you.

Well, I certainly agree that it doesn't seem like we're having rational
discussion; I am having a very hard time understanding the attack you
claim exists. If it were just me, I might think I had a reading
comprehension problem. But given the other responses, maybe you are not
being clear enough?

Paul was nice enough to post an attack scenario based on some of your
comments; I have just replied with my own analysis which, unless there
is an error, shows that it is not a problem.

> Until you can accept that character matters, I can't trust you.

I'm not asking you to trust me. I am asking you to look at the patches I
wrote and decide whether you want to trust _them_ or not[1]. Patches do not
have character.

-Peff

[1]: Actually, I don't even really care whether you trust the patches,
or whether you install them on your system, or whether you recommend
that other people install them. What I do care about is whether there is
a practical attack that works better against qmerge-patched dnscache
than it does against stock dnscache. You seemed to indicate that you
know of one, which is interesting to me (and presumably to others on the
list).
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.