Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
Jeff King <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Mar 05, 2009 at 09:02:20PM -0700, Andy Bradford wrote: > Thus said Jeff King on Thu, 05 Mar 2009 03:09:48 EST: > > > I don't know how many packets in a poisoning attempt is "too much". It > > is my understanding that since Kaminsky's talk, there have been actual > > exploits of unpatched BIND in the wild. So clearly there is a number > > that is "too little to be noticed", at least for some sites. > > It would appear that Dan had already warned that these kinds of attacks > were possible even as early as 2001: > > http://cr.yp.to/djbdns/forgery.html Yes, I don't think any of this has come as a surprise to Dan. I don't know why he didn't bother with duplicate suppression in the first place. Perhaps an attacker sending 16 million packets seemed a lot more infeasible in 2001 than it does now. Maybe he still thinks it's infeasible. At any rate, I agree with his premise: all of these mechanisms are just band-aids to bump the probabilities against an attacker a little bit higher. Non-blind attackers can trivially spoof. The protocol is broken, and the real fix is crypto. But fixing the protocol is a political nightmare and is likely to take some time. In the meantime, I think the band-aids are the best we can do, so they are worth applying if they don't break anything else. Dan may differ on that; I haven't seen a clear plan from him on whether he thinks patches should be applied, whether he is working on a new version, whether he is giving up to focus on dnscurve, or what. -Peff