Re: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: ?Who is Dean Anderson?

Michael Loftis <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <F82557C38338FBFB15CF5E3D@[192.168.1.44]>

--On Friday, March 12, 2010 6:24 PM -0500 Dean Anderson <[email protected]> 
wrote:

> On Fri, 12 Mar 2010, Michael Loftis wrote:
>
>> Scams by multiple people involve collaboration, therefore
>> collaboration is a scam!
>
> No. And of course, the precedent (Scams by multiple people involve
> collaboration) is true while the antecedent is false (collaboration is a
> scam).  Your statement is a fallacy.
>
>> You finally admit that you misunderstand and misapplied the math
>> involved earlier,
>
> I've made no such admission. I've not misapplied any math. You've
> offered no evidence for your assertions. But you just assert fallacies,
> as a diversion from the facts.

<http://marc.info/?l=djbdns&m=126827471711591&w=2>

But you keep quoting the math where you use multiplication, even in this 
current thread.  If you have up to 200 outgoing queries asking for the same 
SOA/A/NS/whatever, that gives the attacker 200 different possibilities of 
success.  If you have *one* then you only have *one* to match.  The more 
outgoing queries (with the random elements QID/port/etc) on the same piece 
of desired data, the more likely you'll be able to force a collision, not 
the less.  Your math assumes the latter, not the former.

You make other assumptions about collaboration, when all you have is 
evidence of data sharing.  We all build in the RFCs, so are we all 
collaborating with their authors?  No.  Kevin Day had no desire to write 
any patches/software in relation to the paper, others did.  Those others 
wrote patches.  That doesn't mean that Kevin collaborated with any of them.

Further your assertion that this is some big scam or hoax, is still 
unsubstantiated, and in direct contradiction to the facts.  Birthday 
attacks are yes nothing new at all.  What was new about this was the 
application of it to DNS.  DJBDNS, because it will allow many outstanding 
queries to be sent out for the same data, happened/happens to be more 
vulnerable to this class of attack, because instead of giving out only one 
winning lottery ticket, it can be simply coerced into giving out a couple 
hundred.  That's simple probability there, you don't need any funny math to 
know that if you've got 200 winning numbers out there you're more likely to 
be holding the winner, yet you keep on asserting this is not the case. 
That this whole thing is a lie, scam, or hoax, perpetrated by some group of 
people, just to sneak patches into djbdns to somehow make it less secure.

>
> I do know a troll when I see one.  I just can't resist replying to it.
>
> 		--Dean
>
> --
> Av8 Internet   Prepared to pay a premium for better service?
> www.av8.net         faster, more reliable, better service
> 617 256 5494
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.