Re: DNSCurve implementation

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Don't use DNSSEC.  Question anything coming out of OpenDNS.

Inline.

On Wed, 24 Feb 2010, Hugo Monteiro wrote:

> Hello,
> 
> After reading on Matthew Dempsky's article, available at
> http://blog.opendns.com/2010/02/23/opendns-dnscurve/ , i couldn't help
> wondering about djbdns "users" feelings on the subject. Also, does
> anyone have up to date information regarding dnscurve support in
> tinydns (if any).

Interesting article on DNSCurve, though it misses the points that DNSSEC
is insecure, but I also question the source for several reasons that
follow. This probably should be a blog article.

OpenDNS, for example, redirects your Google queries to their servers
(source:  recent post on Nanog of this problem).  I think this is a
dubious practice that might be unexpected by most.  OpenDNS also
collects market information about your DNS queries, like who you are
talking to, and roughly how often.  For example, a spike in resolving
Microsoft email servers might indicate a market move.

But most disturbingly, OpenDNS founders are connected to Nanog people
who advocate /closing/ Open DNS recursors of the /very same type/
OpenDNS operates.  It seems some like OpenDNS can run open recursors,
while others "aren't allowed" or are "discouraged" from doing so. This
is a scam, extorting open dns recursor services by means of abuse called
a "reflection attack". Nanog has long been a recruiting ground for
internet abuse.

A very similar scam was run on open relays in the 1990s.  Back in the
1990's some people (who later turned out to be the same people demanding
their closure, operating blacklists) abused open relays. They "claimed"
that open relays somehow promoted spam, but in fact they were the only
abusers.  In fact, since email passing through an open relay is not
anonymous, open relays have no more benefit to abuse than do so-called
"closed relays", so the scam was pretty easy to see from a technical
standpoint. But many were still misled by scammers and extorted by means
of abuse and blacklists.  The scam was that some ISPs were "allowed"  
to run open relays without being molested, often after buying services.  
Anyone who refused was molested by abuse.  I wonder at the coincidence
of the fact that OpenDNS employees have been linked to Chris Neill.  
(Neill claimed to know several OpenDNS 'expats') Neill was a part of the
"Cleveland Spam Gang", one of several gangs of
spammers/abusers/extortionists who were abusing open relays and selling
services. Neill was eventually fired from Verio.
http://www.iadl.org/cn/cn-story.html Some of the "Cleveland Gang" were
linked to the SPEWS blacklist (Steve Sobol)  And now, this same pattern
appears to happening again with open recursor reflection abuse.

The open recursor reflection abuse was first reported a few months after
Dan Kaminsky announced list of 500,000 open recursors at the "Schmoocon"  
hacker convention in October 2005.  The first report of abuse is posted
on Feb 24, 2006 on Nanog. Although Chris Morrow claims these attacks
were going on for 6 years previously, there are no reports or complaints
that I could find. [Morrow is another dubious Nanog character who once
conducted a DOS attack on AV8 Internet in 2005, by placing bogus BGP
route announcements of address space belonging to AV8 Internet without
authorization during a dispute with Worldcom. The Worldcom lawyer
resigned suddenly.]

Then OpenDNS was the beneficiary of the Kaminsky/Vixie cache poisoning
scam. Kaminsky & Vixie conspired to deceive people about DNS Cache
Poisoning, and this was exposed by myself and others.  In the "big
announcement" launching the scam, Kaminsky told people to switch their
DNS service OpenDNS.

So I question the source for those reasons.


> Over here, we're being politely asked to adopt DNSSEC, by one of the
> main govern internet agencies. The fact that apparently dnscurve
> exists only in paper, for the authoritative server software, doesn't
> help much when one tries to propose an alternative.

I keep saying this; word seems to be spreading:

DNSSEC Cache Poisoning has been confirmed just as I described. Note that
many people are now advising to turn off DNSSEC validation.

    Most officially, I discussed it in my DNSSEC NTIA comments:
    http://www.ntia.doc.gov/dns/comments/comment027.pdf 
    in the section on Cache Poisoning. Notably, Vixie et al disputed
    this when discussed on DNSOP and namedroppers. Guess they were wrong
    again.

    If you want to engage in honest uncensored discussion of DNS issues,
    subscribe to dnsop-honest or namedroppers-honest through the 
    interface at lists.iadl.org

    [*] See DNSSEC cache poisoning links contained in
http://lists.iadl.org/pipermail/namedroppers-honest/2010-January/000074.html 
 
    The IETF has known of these problems for a long time, and silenced
    me to keep these problems quiet.

Vixie and the IETF have known about the DNSSEC Cache Poisoning problem
and other DNSSEC problems for a number of years, but they have covered
it up by threatening and silencing critics. Inquiry reveals that DNSSEC
is a scam that threatens the stability of the Internet.

Please be sure to credit me with discovering the DNSSEC flaws. And
please forward this message widely

Thanks,

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.