Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Jeff King <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Thu, Mar 05, 2009 at 09:02:20PM -0700, Andy Bradford wrote:

> Thus said Jeff King on Thu, 05 Mar 2009 03:09:48 EST:
> 
> > I don't know how many packets in a poisoning attempt is "too much". It
> > is my understanding that since Kaminsky's talk, there have been actual
> > exploits of unpatched  BIND in the wild. So clearly  there is a number
> > that is "too little to be noticed", at least for some sites.
> 
> It would appear that Dan had  already warned that these kinds of attacks
> were possible even as early as 2001:
> 
> http://cr.yp.to/djbdns/forgery.html

Yes, I don't think any of this has come as a surprise to Dan. I don't
know why he didn't bother with duplicate suppression in the first place.
Perhaps an attacker sending 16 million packets seemed a lot more
infeasible in 2001 than it does now. Maybe he still thinks it's
infeasible.

At any rate, I agree with his premise: all of these mechanisms are just
band-aids to bump the probabilities against an attacker a little bit
higher. Non-blind attackers can trivially spoof. The protocol is broken,
and the real fix is crypto.

But fixing the protocol is a political nightmare and is likely to take
some time. In the meantime, I think the band-aids are the best we can
do, so they are worth applying if they don't break anything else. Dan
may differ on that; I haven't seen a clear plan from him on whether he
thinks patches should be applied, whether he is working on a new
version, whether he is giving up to focus on dnscurve, or what.

-Peff
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.