Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 1 Mar 2009, Michael Sierchio wrote: > Paul Jarc wrote: > > > qmerge + 200 identical attack queries -> > > dnscache chooses a single new port for a new outgoing query > > > > no-qmerge + 1 attack query -> > > dnscache chooses a single new port for a new outgoing query > > > > I don't see any significant difference between these cases - in > > particular, they seem equally vulnerable to port guessing and to DOS. > > The difference is fairly simple -- the stock behavior is vulnerable > to being flooded with a crafted query, pushing legitimate queries > off the queue. I think this was articulated in a lucid and cogent > manner. Your statement is mostly literally true, but naive. Stock behavior is not _very_ vulnerable. Let's put this in context: DES is vulnerable to cracking, but it not very vulnerable. Ordinary script kiddies probably can't break DES. Similarly MD5 hashs (found in many SSL certificates) are vulnerable, but not very vulnerable. SHA-1 is also vulnerable, but not very vulnerable. Certificates will expire before non-government entities can forge an SHA-1 hash. But you misunderstand other elements. There is nothing 'crafted' about the query. There is nothing about pushing legitimate queries off the queue. > The qmerge patch is makes the system more robust. No, actually, it isn't. It makes one attack (the birthday attack) harder, but makes other attacks easier. Because there is another way to make the birthday attack harder without any negative side effects, this other way is preferable. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000