Re: update on the djbdns bugs? (fwd)

Kevin <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Sorry, but you're reading things that aren't there. Read what you just pasted again, looking for the word "patches" or "code" or anything like that. The only mention of "patches" in any of what you pasted below is from you. 

I was working on a *document* detailing my investigation, nowhere do I say I've written any code. Dan just got involved because I asked him some questions, nowhere does he say he wrote any code. I was originally planning on releasing a *document* without any patches, but Jeff stepped forward and created a patch.

From the very beginning, the web site I threw together (http://www.your.org/dnscache/) said: "These patches were developed by Jeff King, and are released into the public domain."  That was there from day one.

To sum up:

Kevin: Wrote a PDF discussing the weakness.
Jeff: Wrote the patch.
Dan: Not involved at all, other than me sharing my PDF with him before it was made public.

> Then Jeff King turns up with the patches.  And "Mark Johnson"  
> distributes them anonymously with no accountability, with more tweaking.  
> Struck me as just like money-laundering. I called it reputation and
> accountability laundering.

I distributed these patches long before Mark did. I'm easily traceable to being on the internet for 15 years or so. Before I started my consulting company (www.your.org), I was a video game designer for one of the biggest video game companies out there. If you've put quarters in a games at a bar, you've probably played a game I made. I am not anonymous. My work now depends on people trusting my ability to produce secure software, so I am also quite accountable to my reputation. Jeff King (who is a PhD student, whose college would likely frown on him claiming other people's work) emphatically states he wrote the patches, and is also clearly not anonymous. You're saying that it being written by someone who is well known, and distributed by me who is neither anonymous or unaccountable, it's still an issue when someone else who doesn't have our history distributes them again? If John Doe takes an email you posted here and quotes it verbatim, does the original quote become less trustworthy? I don't follow this logic. If you think these specific patches themselves are untrustworthy, the issue you have is with Jeff and/or myself. If you think Mark is sneaking code into his distribution that he's writing himself, do a diff and point out to us where he's writing anything of his own that looks suspicious. If not, Mark has nothing to do with this.

I mean this as honestly and genuinely as I can, Dean... You're in such a rush to find facts to confirm your theories that you're misreading hugely important pieces. Part of the reason that nobody was understanding your previous critiques was that you were discussing an attack technique that has nothing to do with what the paper described, largely because you're assuming that everything we've been talking about is somehow a replica of Dan Kaminsky's work. I'm all for honest criticism of my work, but your critique so far has been based on a misunderstanding of the attack model to start with. Follow that by a mathematical mistake (substituting multiplication for division) that without even looking to see why we came up with different numbers, and you instantly assume it's because everyone else was wrong(and confirming your initial feeling that it was all some scam) rather than checking your math. You (incorrectly) assumed that Dan and I were claiming credit for writing patches, even going so far as to paste old emails in defense of this assumption, without noticing that we never say anything like that. Slow down and work with us before jumping to conclusions and you'll find a MUCH more receptive audience. Remember, I'm the one who gave you my direct phone number and offered to spend as much time as necessary with you until we were on the same page after it was obvious we weren't in agreement.

You're making this far more complicated than it is. :)

-- Kevin


On Mar 11, 2010, at 5:32 PM, Dean Anderson wrote:

> My email records contradict that.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.