Re: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: Who is Dean Anderson?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
The fork offered by "Mark Johnson" via sourceforge, called zinq Emails and other efforts at identifying "Mark Johnson" [email protected], only lead to an email address, and no emails before a couple years ago. No other "Mark Johnson" participated in qmail, djbdns or any other DNS or email list that I could find. "Mark Johnson" appears to be a sockpuppet, possibly operated by one or all of Dempsky, Day, Kaminsky or their associates. The fork contains changes originated by Kevin Day and Dan Kaminsky, which change the way that DJBDNS handles random ports. The initial proposal sent to me by Day seriously weakened DJBDNS to birthday attacks and cache poisoning. The changes distributed by "Mark Johnson" are a variant of these changes. Dan Kaminsky is known to be a hacker who reported identifying 500,000 open DNS recursors to a black-hat convention called Schmoo-con in October 2005. The first attacks using DNS recursors were reported in Februrary, 2006. These recursors were not open, but "half open", that is, open to internal address but not open from external addresses. To identify open recursors would require scanning, and Kaminsky announced no scanning before October 2005. By contrast, groups like CAIDA that regularly scan DNS servers, regularly get complaints about the scanning despite announcements. No complaints of scanning were reported. So I think that the scanning was done piecemeal from a botnet, rather than from a fixed IP. Positing 'discovery by botnet' also explains why half-open recursors were apparently discovered: because they are open to the bots on their internal network. In 2009, Kaminsky was involved in a scam to get people to switch to OpenDNS by claiming to have discovered a flaw in DNS. In fact, the flaw was discovered years earlier, and even the specific scheme of spoofing NS records was tested and discussed in 2006. Kaminsky's claim was debunked by (amoung others) MIT Technology Review. Dempsky is a supporter of the zinq changes and thinks that sock-puppet software distribution is OK. It turns out that Dempsky works for OpenDNS. Other friends of Kaminsky have been linked to uber-spammer Scott Richter. I haven't announced the results of the QuickPoll, yet, but they are unfavorable to Dempsky/Johnson's position. Short enough? --Dean On Tue, 9 Mar 2010, Chris Pugh wrote: > On 8 March 2010 20:51, Dean Anderson <[email protected]> wrote: > > > Similarly, we have a moral duty to make people aware of discredited > > forks of DJBDNS. > > For those of us ( probably only myself ) whom are in the the dark on > this pont, but wish to be enlightened, bearing in mind that Mr > Bernstein has placed his DNS software in the Public Domain, perhaps > you would care to state, in your oipinion, which 'forks' of DJBDNS are > discredited, which dishonest, which not, and why? > > A concise 'potted; response would be great ( so as I don't get lost in > a forest of words ) > > Regards, > > > Chris > > Aside > ==== > > I am pleased to note that the Good Shepherd is ever watchful of his > flock, I am particularly taken with, > > http://cr.yp.to/hardware/build-20060107.html > > where Dr B states, > > 'Turning on the computer. Starting now, be very careful not to touch > anything inside the case. Power will be flowing into the computer in a > moment; if you touch something inside the case, you can electrocute > yourself!' > > Cheers Dan! ;o) > ;o) > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494