Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Fri, 20 Feb 2009, Paul Jarc wrote:

> Dean Anderson <[email protected]> wrote:
> Right, if those people don't have the time/inclination/capacity to
> analyze the actual behavior of the patches.  If we invest the time and
> effort to understand the source, we understand the behavior.  The
> patches won't magically take on new behavior behind our backs based on
> who wrote them.  If they have good behavior, we lose nothing by using
> them, even if they were written by people with bad reputations.

We have been able to analyze the changes, and I have discovered flaws
introduced by the Kaminsky/Day/King changes.

> Reputation is a good basis for initial guesses, but not for
> conclusions.
> 
> You say that Kevin Day is malicious, based on his contact with Dan
> Kaminsky.

Please keep the facts straight, particularly when you attribute to
others words that they didn't use. I didn't say they are malicious--I
have no knowledge of actual malice or actual criminal activity. I say
that Kevin Day and Dan Kaminsky, as a team, are untrustworthy because of
their association with blackhat activity and past false statements.
King's patches are designed by untrustworthy people, and so are
untrustworthy even if King were trustworthy. I have left unstated
whether King is a participant in the scheme or a duped victim. King
subsequently seems intent on laundering their bad reputation, however.
Such intent suggests that he wasn't a victim, but a participant.

> You also say that you were involved in the same off-list conversation
> with them.  By your standard, from the information I have, I should
> conclude that you are malicious.  That actually hangs together much
> more nicely, since you're the one trying to discourage adoption of a
> change that is known to fix one problem, and that has no new
> weaknesses that you've been able to explain in a way that anyone else
> understands.

The patch has a couple weaknesses that has been described.

The one good thing that the patch claims to fix, can be fixed in another 
way that doesn't introduce any weaknesses.

> (I don't actually believe you're malicious.  But from the information
> I have, there's more reason to suspect you than Kevin.)

Nice personal attack, no facts.

Lets review the facts: I'm not assocated with any blackhats, but Kevin
Day is. I haven't lied about not being associated with any blackhats,
but Kevin Day did.  I didn't lie about discovering a DNS flaw, but Dan
Kaminsky did.  I didn't propose introducing a VERY SERIOUS flaw
(ultimately not implemented) into DNScache, but Kaminsky and Kevin did.  
That seems reason to distrust Kevin. If those aren't good reasons for
you, I probably won't trust your judgement on such matters.

In contrast with the facts, you (really Jarc, Dempsky, King et al) are
promoting a patch _designed_ by _blackhats_ which adds in a weaknesses
that I have described; and you (Jarc et al) inexplicibly oppose a patch
that doesn't inject any weakness by not tinkering with more than is
necessary.  You certainly aren't interested in the safest and most
prudent course of action, which seems to suggest that your judgement is
least poor.

> > I have a legitimate analysis of the problem; you have seen it;  but
> > you STILL (if above is any indication) can't even repeat it back to
> > me accurately.
> 
> As far as I've seen, *no one* can repeat it back to you.  *No one* has
> understood what concrete problems exist in the qmerge patch.

Well, indeed, I __can't__ help it if you don't understand basic concepts
of random numbers, and don't understand the the port number selection in
DNScache isn't perfectly random. The concept of random numbers seems
clear enough to many others, but I agree it might be a difficult concept
for many not trained in math. I won't call anyone stupid who doesn't get
it.

> It could be that everyone else here is too stupid to measure up to
> you, but it seems rather more likely that either you simply haven't
> done a good enough job of explaining the problems, or you're mistaken
> about their existence.

Nice try at "everyone else here". Seems like its just Jeff King, Kevin
Day, Matt Dempsky, and Paul Jarc. And Mark Johnson (who I still can't
identify) hasn't said a word since I asked for references. That's not
everyone. At least, I hope not.

It could indeed be the case that some are too stupid to measure up, but
I choose not to use those terms. I note your rhetorical trick of trying
to make it seem like I am calling "everyone else" stupid.  It could be
that some people are here trying to promote a blackhat's patches. Or it
could be they have very poor judgement.

What is certain is that there is no mistake about the randomness of UDP
port selection (not strongly random); no mistake about the existance of
introduced weaknesses by increasing the dependence on weakly-random UDP
port randomness; no mistake about reducing the number of query/response
pairs enabling a DOS attack on those two packets. 

It is certain that there is another way (TCP fallback) to make the
birthday attack more difficult that doesn't introduce any weaknesses.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.