Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 20 Feb 2009, Paul Jarc wrote: > Dean Anderson <[email protected]> wrote: > Right, if those people don't have the time/inclination/capacity to > analyze the actual behavior of the patches. If we invest the time and > effort to understand the source, we understand the behavior. The > patches won't magically take on new behavior behind our backs based on > who wrote them. If they have good behavior, we lose nothing by using > them, even if they were written by people with bad reputations. We have been able to analyze the changes, and I have discovered flaws introduced by the Kaminsky/Day/King changes. > Reputation is a good basis for initial guesses, but not for > conclusions. > > You say that Kevin Day is malicious, based on his contact with Dan > Kaminsky. Please keep the facts straight, particularly when you attribute to others words that they didn't use. I didn't say they are malicious--I have no knowledge of actual malice or actual criminal activity. I say that Kevin Day and Dan Kaminsky, as a team, are untrustworthy because of their association with blackhat activity and past false statements. King's patches are designed by untrustworthy people, and so are untrustworthy even if King were trustworthy. I have left unstated whether King is a participant in the scheme or a duped victim. King subsequently seems intent on laundering their bad reputation, however. Such intent suggests that he wasn't a victim, but a participant. > You also say that you were involved in the same off-list conversation > with them. By your standard, from the information I have, I should > conclude that you are malicious. That actually hangs together much > more nicely, since you're the one trying to discourage adoption of a > change that is known to fix one problem, and that has no new > weaknesses that you've been able to explain in a way that anyone else > understands. The patch has a couple weaknesses that has been described. The one good thing that the patch claims to fix, can be fixed in another way that doesn't introduce any weaknesses. > (I don't actually believe you're malicious. But from the information > I have, there's more reason to suspect you than Kevin.) Nice personal attack, no facts. Lets review the facts: I'm not assocated with any blackhats, but Kevin Day is. I haven't lied about not being associated with any blackhats, but Kevin Day did. I didn't lie about discovering a DNS flaw, but Dan Kaminsky did. I didn't propose introducing a VERY SERIOUS flaw (ultimately not implemented) into DNScache, but Kaminsky and Kevin did. That seems reason to distrust Kevin. If those aren't good reasons for you, I probably won't trust your judgement on such matters. In contrast with the facts, you (really Jarc, Dempsky, King et al) are promoting a patch _designed_ by _blackhats_ which adds in a weaknesses that I have described; and you (Jarc et al) inexplicibly oppose a patch that doesn't inject any weakness by not tinkering with more than is necessary. You certainly aren't interested in the safest and most prudent course of action, which seems to suggest that your judgement is least poor. > > I have a legitimate analysis of the problem; you have seen it; but > > you STILL (if above is any indication) can't even repeat it back to > > me accurately. > > As far as I've seen, *no one* can repeat it back to you. *No one* has > understood what concrete problems exist in the qmerge patch. Well, indeed, I __can't__ help it if you don't understand basic concepts of random numbers, and don't understand the the port number selection in DNScache isn't perfectly random. The concept of random numbers seems clear enough to many others, but I agree it might be a difficult concept for many not trained in math. I won't call anyone stupid who doesn't get it. > It could be that everyone else here is too stupid to measure up to > you, but it seems rather more likely that either you simply haven't > done a good enough job of explaining the problems, or you're mistaken > about their existence. Nice try at "everyone else here". Seems like its just Jeff King, Kevin Day, Matt Dempsky, and Paul Jarc. And Mark Johnson (who I still can't identify) hasn't said a word since I asked for references. That's not everyone. At least, I hope not. It could indeed be the case that some are too stupid to measure up, but I choose not to use those terms. I note your rhetorical trick of trying to make it seem like I am calling "everyone else" stupid. It could be that some people are here trying to promote a blackhat's patches. Or it could be they have very poor judgement. What is certain is that there is no mistake about the randomness of UDP port selection (not strongly random); no mistake about the existance of introduced weaknesses by increasing the dependence on weakly-random UDP port randomness; no mistake about reducing the number of query/response pairs enabling a DOS attack on those two packets. It is certain that there is another way (TCP fallback) to make the birthday attack more difficult that doesn't introduce any weaknesses. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000