Re: Quick Poll: Would you trust system software from an anonymous source?

[email protected] (Paul Jarc)
Newsgroups gmane.network.djbdns
Organization What did you have in mind? A short, blunt, human pyramid?
Message-ID <[email protected]>
Dean Anderson <[email protected]> wrote:
> If the records happen to exist, then its just like the RFC described as
> example:  Spoofing wrong NXdomain is possible. But If they don't exist,
> then spoofing NXDomain is still possible. We knew that before.

Spoofing NXDOMAIN has nothing to do with Kaminsky's attack.  The
forged answers may or may not be NXDOMAIN; it's irrelevant.  The
geniune answer may or may not be NXDOMAIN; it's also irrelevant.

> It took 26 million packets in January 2008 to spoof dnscache. It
> takes 26 million packets to spoof dnscache now.  There was no
> (non-gratuitous) change and no discovery.

Kaminsky didn't reduce the number of packets required.  He reduced the
time required.  Before, when one attempt failed and the geniune answer
was cached, the attacker would havev to wait out the TTL, then try
again.  Kaminsky's new technique was to immediately move on to a
different qname rather than waiting.  Of course that was always
possible, but as far as I know, no one had done it before (discovery,
not invention).  Do you have references of anyone earlier sidestepping
the TTL-wait by moving on to a different qname?


paul
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.