Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 20 Feb 2009, Matthew Dempsky wrote: > On Fri, Feb 20, 2009 at 2:32 PM, Dean Anderson <[email protected]> wrote: > > Another scenario is they DOS attack the authority server, and cause > > either the single query or the single response to be lost, enabling a > > longer time on the attack. > > This attack applies to unpatched dnscache too. If you DOS the > authority server and cause any of the responses to be lost, then > dnscache's corresponding query ports are vulnerable to attack for a > longer period of time. You understand that if unpatched dnscache > sends 200 query packets for the same name, that an attacker only has > to successfully forge a response packet to one of these queries for > his attack to succeed, right? Wrong yet again: On an unpatched DNScache, it sends up to 200 queries in response to the birthday attack, and so it expects up to 200 responses. Of course, if an attacker only sends a single query at a time, rather than the fastest birthday attack, there will only be a single query/response pair, but then one can't run the birthday attack very fast, and it will take quite a bit longer to succeed (billions of packets, because the attacker restricted themselves to one port). > If you're going to continue bad mouthing Kevin Day and Jeff King, I > expect you to describe an attack that is more effective against > dnscache-with-qmerge than dnscache-without-qmerge. I haven't 'bad-mouthed' anyone. I've only stated their associations and the facts. And indeed, I have described just such attacks due to weaknesses introduced by the qmerge patches. It is you who can't seem to come up with credible contrary claims. Every thing you've come up with so far hasn't been credible: nor in the least way mathematical or cryptographic in nature. Nor have you give even a SINGLE reason to reject my proposed changes. > Is there anyone on this list other than Dean that thinks his arguments > against Kevin's qmerge patch are at all credible? If not, I'm going > to give up on replying to his emails until I see one with concrete > details of an attack against the patch. I'm tired of repeatedly > asking him to specify one, and his lack of logical reasoning is too > infuriating for me to continue without good cause. Likewise. What I know is that _I_ won't be running discredited, blackhat-influenced, vulnerable software, and we'll just have to see what others think about who is more credible. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000