Re: squirting spray foam into the crack at the bottom of the BAW
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
One only needs to fall back to TCP in that case. An attacker in the path would be able to spoof in one packet, most of the time. So if we detect a birthday attack, then we know the attacker isn't in the path. And TCP is more than sufficient to prevent attacks from attackers who are not in the path. --Dean On Sat, 13 Mar 2010, David Nicol wrote: > On Fri, Mar 12, 2010 at 3:48 PM, Dean Anderson <[email protected]> wrote: > > server. Like I said before, an IDS should detect a 26 million packet > > attack before it succeeds. ÃÂ DJB has said something similar. > > > > [...] > > > > There is no way that the "birthday attack window" can be closed, > > Safety currently appears to require an Intrusion Detection System, so building > an IDS into a resolver (as has been done, see > http://marc.info/?l=djbdns&m=124356186626355 > ) might be considered the equivalent of squirting some expanding foam > into the crack at the bottom of the window in question. > > What additional measures? second, third, fourth opinions from other > servers presumably not under the same attack, reached over VPN links. > Build that into something, a network of resilient dns servers that > create a mesh of secure tcp links between each other and start > chatting over them when something appears amiss? > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494