Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 1 Mar 2009, Paul Jarc wrote: > Dean Anderson <[email protected]> wrote: > > By having DNScache use fewer ports, any non-random behavior of > > randombind has a greater impact on the fewer ports used by DNScache. > > DNScache becomes more predictable for a longer. Attackers can > > exploit that non-randomness to their benefit. > > How, exactly? What is the algorithm the attacker would use? I already described two scenarios. > Knowing the algorithm is absolutely crucial. Balderdash. Knowing the mathematics is crucial. Public implementation of cracks is an exercise that I have no interest in. > I understand the algorithm for the birthday attack, but I haven't been > able to figure out what the algorithm would be for the attack(s) > you're talking about. It doesn't matter _how_, it matters _that_: that the number returned by randombind isn't a strong random number, and it matters that when this not-random return value is used less often and is THE SINGLE PORT for a Query tuple, there is greater vulnerablity through negative side effects such as a single pair of query/response packets. > > No, if any of the other 199 are responded before the attack is > > successful, then the query is answered and the attack fails. > > Ok, I think we've found a point where we have different understandings > of stock dnscache's behavior. [long timeconsuming nonsense deleted] The important point is that these 199 other responses aren't prevented, the end user isn't poisoned on that particular query, and each could potentially be cached preventing poison. I will not be sending further argument. Instead, I will be offering a distribution of DJBDNS without the Qmerge patch. Instead, it will detect a birthday attack in progress and fall back to TCP. My version will be trustworthy, and I will not accept patches with negative side effects from untrustworthy patches. So, if you want trustworthy, robust software, get my version. If you want the blackhat version, get Jeff King's Kaminsky/Day patches. I never did get a reference for Mark Johnson. Does anyone know him personally? Any background? --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000