Re: [Asrg] DNSSEC is NOT secure end to end

der Mouse <mouse@Rodents-Montreal.ORG> Wed, 10 June 2009 23:24 UTC

Return-Path: <mouse@Sparkle.Rodents-Montreal.ORG>
X-Original-To: asrg@core3.amsl.com
Delivered-To: asrg@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 8279D3A6987 for <asrg@core3.amsl.com>; Wed, 10 Jun 2009 16:24:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.185
X-Spam-Level:
X-Spam-Status: No, score=-9.185 tagged_above=-999 required=5 tests=[AWL=0.803, BAYES_00=-2.599, HELO_MISMATCH_ORG=0.611, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g09h+HOhfZvS for <asrg@core3.amsl.com>; Wed, 10 Jun 2009 16:24:39 -0700 (PDT)
Received: from Sparkle.Rodents-Montreal.ORG (Sparkle.Rodents-Montreal.ORG [216.46.5.7]) by core3.amsl.com (Postfix) with ESMTP id C69463A6358 for <asrg@irtf.org>; Wed, 10 Jun 2009 16:24:38 -0700 (PDT)
Received: (from mouse@localhost) by Sparkle.Rodents-Montreal.ORG (8.8.8/8.8.8) id TAA11702; Wed, 10 Jun 2009 19:24:44 -0400 (EDT)
From: der Mouse <mouse@Rodents-Montreal.ORG>
Message-Id: <200906102324.TAA11702@Sparkle.Rodents-Montreal.ORG>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 8bit
X-Erik-Conspiracy: There is no Conspiracy - and if there were I wouldn't be part of it anyway.
X-Message-Flag: Microsoft: the company who gave us the botnet zombies.
Date: Wed, 10 Jun 2009 19:15:39 -0400
To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
In-Reply-To: <4A3039BC.1050608@necom830.hpcl.titech.ac.jp>
References: <200905302032.n4UKVxaZ048822@givry.fdupont.fr> <4A21C0CB.8070409@necom830.hpcl.titech.ac.jp> <8EFB68EAE061884A8517F2A755E8B60A1EF83F8661@NA-EXMSG-W601.wingroup.windeploy.ntdev.microsoft.com> <4A252B54.6020508@necom830.hpcl.titech.ac.jp> <1244061519.2778.62.camel@bravo.isode.net> <4A29EC02.6000807@necom830.hpcl.titech.ac.jp> <1244490849.2822.21.camel@bravo.isode.net> <4A2DA4C8.2000304@necom830.hpcl.titech.ac.jp> <1244535420.2760.64.camel@bravo.isode.net> <4A2EFBCE.5000502@necom830.hpcl.titech.ac.jp> <20090610165911.GH33231@shinkuro.com> <4A3039BC.1050608@necom830.hpcl.titech.ac.jp>
Subject: Re: [Asrg] DNSSEC is NOT secure end to end
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Wed, 10 Jun 2009 23:24:44 -0000

>>>> With DNSSEC, a security aware resolver will want to check the
>>>> signature.
>>> Except for glue A.
> which makes DNSSEC as insecure as plain old DNS.

Um, I think I disagree.

Given a system with many points of compromise and a system with fewer
points of compromise, other things being equal, I think it's fair to
say the latter is more secure, even if successful compromises lead to
approximately equal levels of damage.

Is the difference in this case substantial?  I don't know; I haven't
looked at any of the attacks in enough detail to have more than wild
guesses at their difficulties.  But I think "as insecure as" is
inaccurate, even if the truth is something more like "only marginally
more secure than".

In particular, domains that do not need glue records are not threatened
by this.  (Of course, their nameserver address records need securing,
or there is a similar attack that could work.  But it increases the
complexity of the attack at the very least, and once the root zone is
signed it will be theoretically possible, at least, to avoid the
problem completely.)

/~\ The ASCII				  Mouse
\ / Ribbon Campaign
 X  Against HTML		mouse@rodents-montreal.org
/ \ Email!	     7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B