Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Sun, 1 Mar 2009, Paul Jarc wrote:

> Dean Anderson <[email protected]> wrote:
> > By having DNScache use fewer ports, any non-random behavior of
> > randombind has a greater impact on the fewer ports used by DNScache.
> > DNScache becomes more predictable for a longer.  Attackers can
> > exploit that non-randomness to their benefit.
> 
> How, exactly?  What is the algorithm the attacker would use?

I already described two scenarios. 

> Knowing the algorithm is absolutely crucial.  

Balderdash. Knowing the mathematics is crucial. Public implementation of
cracks is an exercise that I have no interest in.

> I understand the algorithm for the birthday attack, but I haven't been
> able to figure out what the algorithm would be for the attack(s)
> you're talking about.

It doesn't matter _how_, it matters _that_:  that the number returned by
randombind isn't a strong random number, and it matters that when this
not-random return value is used less often and is THE SINGLE PORT for a
Query tuple, there is greater vulnerablity through negative side effects
such as a single pair of query/response packets.

> > No, if any of the other 199 are responded before the attack is
> > successful, then the query is answered and the attack fails.
> 
> Ok, I think we've found a point where we have different understandings
> of stock dnscache's behavior. 

[long timeconsuming nonsense deleted]

The important point is that these 199 other responses aren't prevented,
the end user isn't poisoned on that particular query, and each could
potentially be cached preventing poison.



I will not be sending further argument.  Instead, I will be offering a
distribution of DJBDNS without the Qmerge patch. Instead, it will detect
a birthday attack in progress and fall back to TCP.  My version will be
trustworthy, and I will not accept patches with negative side effects
from untrustworthy patches.  So, if you want trustworthy, robust
software, get my version.  If you want the blackhat version, get Jeff
King's Kaminsky/Day patches.

I never did get a reference for Mark Johnson.  Does anyone know him 
personally?  Any background?  

		--Dean


-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.