Re: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: Who is Dean Anderson?
Kevin <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Mar 9, 2010, at 5:49 PM, Dean Anderson wrote: > The fork offered by "Mark Johnson" via sourceforge, called zinq > > Emails and other efforts at identifying "Mark Johnson" > [email protected], only lead to an email address, and no emails before > a couple years ago. No other "Mark Johnson" participated in qmail, > djbdns or any other DNS or email list that I could find. "Mark Johnson" > appears to be a sockpuppet, possibly operated by one or all of Dempsky, > Day, Kaminsky or their associates. > > The fork contains changes originated by Kevin Day and Dan Kaminsky, > which change the way that DJBDNS handles random ports. The initial > proposal sent to me by Day seriously weakened DJBDNS to birthday attacks > and cache poisoning. The changes distributed by "Mark Johnson" are a > variant of these changes. > Dean, this really needs to stop. For those of you who weren't present for the beginning of this from a year ago: * I discoverd that dnscache is more susceptible to a certain kind of cache poisoning than BIND and other resolvers. I have never claimed this is undiscovered by anyone else, but rather unknown to most dnscache USERS, and that a simple patch would make this poisoning much more difficult with no down sides. * I gave you an advance copy of my findings, my direct phone number, and offer to discuss the matter with you before it is made public. You said you were too busy. * Immediately after I make my report (and a patch written by Jeff King, not me) public, you claim that this somehow makes things worse, using circular logic that as far as I can tell nobody reading this list other than you could understand/agree with. Your argument wasn't even right or wrong, it was based on so many misunderstandings that nobody could even follow what you were trying to say the problem was. * The basis of the vulnerability was compiled into a much more rigorously researched paper by several Georgia Tech students, which was submitted as part of NDSS '09. If you honestly believe there is a misunderstanding in this paper that could make things worse, it somehow escaped a lot of review by professional security researchers. http://www.isoc.org/isoc/conferences/ndss/09/pdf/15.pdf * If I am truly a "black hat" (as you seem to like calling us) who is trying to sneak weaknesses into DNS software, you should really warn Microsoft because I must have fooled them as well. ( http://www.microsoft.com/technet/security/bulletin/ms09-008.mspx#EC4AG ) * Dan Kaminksy has nothing to do with any of this, both he and I have said so several times. I referenced his work in my report, that's about it. I have never met Dan Kaminsky. I have never worked with Dan Kaminsky. Or Paul Vixie. Or Mark Johnson. Or any of the other people who you're making claims about. Yet a year later, you're still claiming we're associates of some kind, up to no good together. * The patch has nothing to do with how DJBDNS handles "random ports". I don't know if this has changed, but you admitted about half way through the fiasco that you hadn't even read the documentation out of fear that I was somehow trying to hack you with a PDF. I offered to send you the plaintext LaTeX sources or a .TXT version, but you never responded to this. * The only objection anyone has made to any of this, other than yourself, is that "DJB said this was there all along, this isn't news" which I do not disagree with. I have never claimed what I brought forward was new, or something that DJB was unaware of. My only goal was to further harden dnscache. * The fact that this is one of Mark's first public software projects (he is a student, correct?) is not unusual/bad. The source code is there, if he were sneaking in "bad things" someone would notice. Please stop discouraging new developers from getting involved in DNS, it hurts all of us. Both my and Mark's first contributions to the djbdns community has resulted in a witch hunt instigated by you. Even if we were completely wrong about everything we have done, this is not an appropriate response. * Endless diatribes about reputation, completely unsubstantiated speculation of dishonesty, and continual assertions of some kind of relationship between people who are adamant that there is none is getting extremely tiresome for the rest of us who just want to discuss DNS. Everyone in the world who has done something you don't like are somehow associated, and you'll keep annoying all of us until you somehow prove it. Your continued claims are bordering on libel, and well into "why aren't you in my kill file yet?" I've stayed out of all of this because it's getting so silly, but I'm just trying to make sure that the new members of this list aren't taking silence as some kind of admission of guilt. This is all I've got to say on the matter, please take this discussion somewhere more appropriate.