Re: Quick Poll: Would you trust system software from an anonymous source?
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 12 Mar 2010, Dean Anderson wrote: > > Kaminsky didn't reduce the number of packets required. He reduced the > > time required. > > Nope. Didn't do that either. The time depends on the rate at which > packets are sent. Kaminsky didn't invent a way to send packets faster. Hate to reply to my own message. The attack on BIND took on 65536 packets for brute force; easily possible on the //first try// on a LAN. I rather doubt that there was any fallacy among crackers that TTL somehow made the attack much harder; TTL is only relevant if one was spoofing a particular record and the attack failed on the first try. (not likely with BIND) But in that case it was quite likely to succeed on the second try. By contrast, dnscache was (and still is) nearly impervious to a cache poisoning attack---unless the attacker is in the path to the authority server. Like I said before, an IDS should detect a 26 million packet attack before it succeeds. DJB has said something similar. The BIND patch was also sold to people as "closing the birthday attack window", which was false there, also. At best, BIND now has a 26 million packet birthday attack. At worst, less than that. It simply //cannot// be any better than dnscache using the same bits in the packet. It could be worse. There is no way that the "birthday attack window" can be closed, and the effort required can't be increased without adding more random bits in the packet. Fooling around with how the server manages ports doesn't increase that, but can only add harms, like make successful spoofs completely consistent to clients and harder to detect. //Every// fact that Kaminsky et al has asserted turns out to be false and is discredited: from the "preventing birthday attack" to the "roullette logic", to the anonymous distribution, to the dissembling about non-collaboration with each other. Their deceptive claims serve only to financially benefit OpenDNS and perhaps BIND, and harm DJBDNS. In short, its a scam. I might have said that before, a couple years ago. Along with others who noticed nothing was discovered. Have a good weekend. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494