Re: okay already

Dean Anderson <[email protected]> Tue, 23 Mar 2010 11:19:35 -0400 (EDT)
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Mon, 22 Mar 2010, Michael Loftis wrote:

> 
> 
> --On Monday, March 22, 2010 3:56 PM -0400 Dean Anderson <[email protected]> 
> wrote:
> 
> 
> > It occurs to me that another effect of the King/Day/Kaminksy/Vixie
> > crack-to-make-forgery-consistent patch is that a slew of repeated
> > queries will be sent to different nameservers, not all of which might be
> > in the path.  By limiting to one query, a successfull interception
> > in-path to one nameserver, the attacker is guaranteed to get all the
> > queries outstanding.  The patch really does make cracking DNS consistent
> > and virtually undetectable.
> 
> What you're totally missing, and have been totally misssing, and has been 
> tried to explain to you, is that, unpatched, it's MANY orders of magnitude 
> *easier* to get false data into the cache and propagated to users.  

The math does not hold for your claim.  It holds for mine, though.


> Quit talking crap about things you don't understand, or worse, don't know 
> anything about, it makes you appear really stupid.

Yes, it does make someone appear stupid. But they are actually 
just dishonest Vixie hucksters trying to mislead people by lying.

		--Dean


-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494