RE: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: ?Who is Dean Anderson?

"Edward Finlayson" <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Sirs,

Please stop this rather pathetic flame war, of ultimate insignificance and do me the favour of unsubscribing me from this ranting list. I hereby retract my opt-in status and require immediate removal from the list. Thereby leaving you to ignore my former request and still ensuring that I do not have to endure the traffic.

Regards,

Edward Finlayson.

-----Original Message-----
From: Jeff King [mailto:[email protected]] 
Sent: 13 March 2010 07:26
To: [email protected]
Subject: Re: Dishonest Forks? | Was - Re: [Namedroppers-honest] Brian Smith asks: ?Who is Dean Anderson?

On Fri, Mar 12, 2010 at 10:07:33AM -0500, Dean Anderson wrote:

> > An attacker does not succeed by guessing your port. He succeeds by
> > guessing your port and qid pair.
> 
> Yes. Thats a reasonable way to analyze it, IF you are really only going
> send only a 200 of packets. We aren't. We are going to brute force the
> qid, so they aren't random.  Just like the source and dest IP addresses
> aren't random.  To match, you have to have the right set of IP addresses
> too.

OK, I think I see now why you did the math the way you did. You are
trying to birthday-attack the port, and _then_ brute force the qid.
Which is why you use 64510 for the first parameter (random space of the
urn), and then divide the resulting probability by 65536.

But that is not the best way for an attacker to proceed. He can birthday
attack the whole random space simultaneously. Which is why using my
method, the attacker has to send fewer packets (16 million versus your
28 million). Your attack is suboptimal from the attacker's perspective.

> There is no expectation value here.  (Sum of tries * value of try)  
> would give an expected port number, which is nonsense.  There is a pure 
> probability.

No, the probability is only the means to an expectation.  The number we
are interested in is how many packets must the attacker send to achieve
a high confidence of success.

-Peff
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.