Re: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: ?Who is Dean Anderson?
Michael Loftis <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <F82557C38338FBFB15CF5E3D@[192.168.1.44]> |
--On Friday, March 12, 2010 6:24 PM -0500 Dean Anderson <[email protected]> wrote: > On Fri, 12 Mar 2010, Michael Loftis wrote: > >> Scams by multiple people involve collaboration, therefore >> collaboration is a scam! > > No. And of course, the precedent (Scams by multiple people involve > collaboration) is true while the antecedent is false (collaboration is a > scam). Your statement is a fallacy. > >> You finally admit that you misunderstand and misapplied the math >> involved earlier, > > I've made no such admission. I've not misapplied any math. You've > offered no evidence for your assertions. But you just assert fallacies, > as a diversion from the facts. <http://marc.info/?l=djbdns&m=126827471711591&w=2> But you keep quoting the math where you use multiplication, even in this current thread. If you have up to 200 outgoing queries asking for the same SOA/A/NS/whatever, that gives the attacker 200 different possibilities of success. If you have *one* then you only have *one* to match. The more outgoing queries (with the random elements QID/port/etc) on the same piece of desired data, the more likely you'll be able to force a collision, not the less. Your math assumes the latter, not the former. You make other assumptions about collaboration, when all you have is evidence of data sharing. We all build in the RFCs, so are we all collaborating with their authors? No. Kevin Day had no desire to write any patches/software in relation to the paper, others did. Those others wrote patches. That doesn't mean that Kevin collaborated with any of them. Further your assertion that this is some big scam or hoax, is still unsubstantiated, and in direct contradiction to the facts. Birthday attacks are yes nothing new at all. What was new about this was the application of it to DNS. DJBDNS, because it will allow many outstanding queries to be sent out for the same data, happened/happens to be more vulnerable to this class of attack, because instead of giving out only one winning lottery ticket, it can be simply coerced into giving out a couple hundred. That's simple probability there, you don't need any funny math to know that if you've got 200 winning numbers out there you're more likely to be holding the winner, yet you keep on asserting this is not the case. That this whole thing is a lie, scam, or hoax, perpetrated by some group of people, just to sneak patches into djbdns to somehow make it less secure. > > I do know a troll when I see one. I just can't resist replying to it. > > --Dean > > -- > Av8 Internet Prepared to pay a premium for better service? > www.av8.net faster, more reliable, better service > 617 256 5494 > >