Re: okay already
Dean Anderson <[email protected]> Tue, 23 Mar 2010 11:19:35 -0400 (EDT)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 22 Mar 2010, Michael Loftis wrote: > > > --On Monday, March 22, 2010 3:56 PM -0400 Dean Anderson <[email protected]> > wrote: > > > > It occurs to me that another effect of the King/Day/Kaminksy/Vixie > > crack-to-make-forgery-consistent patch is that a slew of repeated > > queries will be sent to different nameservers, not all of which might be > > in the path. By limiting to one query, a successfull interception > > in-path to one nameserver, the attacker is guaranteed to get all the > > queries outstanding. The patch really does make cracking DNS consistent > > and virtually undetectable. > > What you're totally missing, and have been totally misssing, and has been > tried to explain to you, is that, unpatched, it's MANY orders of magnitude > *easier* to get false data into the cache and propagated to users. The math does not hold for your claim. It holds for mine, though. > Quit talking crap about things you don't understand, or worse, don't know > anything about, it makes you appear really stupid. Yes, it does make someone appear stupid. But they are actually just dishonest Vixie hucksters trying to mislead people by lying. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494