Re: okay already
Michael Loftis <[email protected]> Wed, 24 Mar 2010 13:04:42 -0600
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <BB2504F73056E258AA30775D@[192.168.1.44]> |
--On Wednesday, March 24, 2010 2:37 PM -0400 Dean Anderson <[email protected]> wrote: > All of the links cited below by Loftis are known to be BS, and have been > previously exposed as fraudulent false claims. Loftis himself has been > exposed as being a former MAPS employee with no genuine interest or > particular knowledge of DNS or DJB DNS. So, you're including the US CERT in this supposed list of "hoaxers" now too? And yet more of your great faulty logic Dean. Someone worked at a company N years ago (in my case, for about a month something like 7 years ago, and I worked for Margie Arbon, not Paul Vixie. She and I had a personality conflict and some bad miscommunications. I met Paul, several times, as well as some of the ISC folks, but it's hard not to when you work in the same office complex), must therefore then, and now, support any and all actions by that company, in perpetuity! This is beginning to sound a lot like libel. You draw assumptions and connections out of very thin air, and then make some very bold accusations based on those assumptions. Further, you don't know me at all, I don't recall ever meeting you, or seeing anything other than your unsubstantiated claims against some sort of mysterious DNS Cabal, Vixie Cartel, Kaminsky Hoax, etc. Kaminsky never claimed to invent anything new, what was discovered is a way in which the birthday attacks could be made many orders of magnitude more successful. Unpatched DJBDNS, because it will send out many queries for the same data, is somewhere around 200x more likely to fall prey to cache poisoning. No nefarious smoke and mirrors, nothing of the sort. It's been very clearly explained, the math was checked by real statisticians before and after the fact and found to be sound. There's no way to precisely measure these things, but they certainly can be estimated, in a number of ways. DNS, as a protocol, has security flaws, we all know that. Some implementations make these weaknesses more apparent, some make them less. TCP is also flawed, with the same implementation issues. They both make lots of assumptions about the trustworthiness of the networks they're running over. > > There is no point in rehashing the discussion of the last month or so, > which was itself a rehash of prior discussion debunking and exposing as > fraudulent the claims of Day, Kaminsky, and King. > > > --Dean