Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Fri, 20 Feb 2009, Matthew Dempsky wrote:

> On Fri, Feb 20, 2009 at 2:32 PM, Dean Anderson <[email protected]> wrote:
> > Another scenario is they DOS attack the authority server, and cause
> > either the single query or the single response to be lost, enabling a
> > longer time on the attack.
> 
> This attack applies to unpatched dnscache too.  If you DOS the
> authority server and cause any of the responses to be lost, then
> dnscache's corresponding query ports are vulnerable to attack for a
> longer period of time.  You understand that if unpatched dnscache
> sends 200 query packets for the same name, that an attacker only has
> to successfully forge a response packet to one of these queries for
> his attack to succeed, right?

Wrong yet again: On an unpatched DNScache, it sends up to 200 queries in
response to the birthday attack, and so it expects up to 200 responses.  
Of course, if an attacker only sends a single query at a time, rather
than the fastest birthday attack, there will only be a single
query/response pair, but then one can't run the birthday attack very
fast, and it will take quite a bit longer to succeed (billions of
packets, because the attacker restricted themselves to one port).

> If you're going to continue bad mouthing Kevin Day and Jeff King, I
> expect you to describe an attack that is more effective against
> dnscache-with-qmerge than dnscache-without-qmerge.

I haven't 'bad-mouthed' anyone. I've only stated their associations and
the facts. 

And indeed, I have described just such attacks due to weaknesses
introduced by the qmerge patches.  It is you who can't seem to come up
with credible contrary claims.  Every thing you've come up with so far
hasn't been credible: nor in the least way mathematical or cryptographic
in nature.

Nor have you give even a SINGLE reason to reject my proposed changes.

> Is there anyone on this list other than Dean that thinks his arguments
> against Kevin's qmerge patch are at all credible?  If not, I'm going
> to give up on replying to his emails until I see one with concrete
> details of an attack against the patch.  I'm tired of repeatedly
> asking him to specify one, and his lack of logical reasoning is too
> infuriating for me to continue without good cause.

Likewise. 

What I know is that _I_ won't be running discredited,
blackhat-influenced, vulnerable software, and we'll just have to see
what others think about who is more credible.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.