Kaminsky, Cache Poisoning, and Censorship
Dean Anderson <dean@av8.com> Fri, 15 August 2008 13:38 UTC
Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 047AE3A6DC0; Fri, 15 Aug 2008 06:38:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -104.071
X-Spam-Level:
X-Spam-Status: No, score=-104.071 tagged_above=-999 required=5 tests=[AWL=2.229, BAYES_00=-2.599, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PJCNr-QOfV6l; Fri, 15 Aug 2008 06:38:53 -0700 (PDT)
Received: from psg.com (psg.com [147.28.0.62]) by core3.amsl.com (Postfix) with ESMTP id C19BC3A6DBC; Fri, 15 Aug 2008 06:38:53 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KTzOf-000IFH-UD for namedroppers-data@psg.com; Fri, 15 Aug 2008 13:31:17 +0000
Received: from [66.92.146.20] (helo=stora.ogud.com) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <namedroppers@stora.ogud.com>) id 1KTzOa-000IEc-UC for namedroppers@ops.ietf.org; Fri, 15 Aug 2008 13:31:15 +0000
Received: from stora.ogud.com (localhost [127.0.0.1]) by stora.ogud.com (8.14.2/8.14.2) with ESMTP id m7FDV7ID019053 for <namedroppers@ops.ietf.org>; Fri, 15 Aug 2008 09:31:07 -0400 (EDT) (envelope-from namedroppers@stora.ogud.com)
Received: (from namedroppers@localhost) by stora.ogud.com (8.14.2/8.14.2/Submit) id m7FDV7KD019052 for namedroppers@ops.ietf.org; Fri, 15 Aug 2008 09:31:07 -0400 (EDT) (envelope-from namedroppers)
Received: from [130.105.36.66] (helo=cirrus.av8.net) by psg.com with esmtps (TLSv1:DES-CBC3-SHA:168) (Exim 4.69 (FreeBSD)) (envelope-from <dean@av8.com>) id 1KTjXN-000Hd3-JN for namedroppers@ops.ietf.org; Thu, 14 Aug 2008 20:35:15 +0000
Received: from citation2.av8.net (citation2.av8.net [130.105.12.10]) (authenticated bits=0) by cirrus.av8.net (8.12.11/8.12.11) with ESMTP id m7EKVrSO028525 (version=TLSv1/SSLv3 cipher=EDH-RSA-DES-CBC3-SHA bits=168 verify=NO); Thu, 14 Aug 2008 16:31:58 -0400
Date: Thu, 14 Aug 2008 16:31:52 -0400
From: Dean Anderson <dean@av8.com>
X-X-Sender: dean@citation2.av8.net
To: Ben Laurie <ben@links.org>, Alex Bligh <alex@alex.org.uk>, David Conrad <drc@virtualized.org>, bert hubert <bert.hubert@netherlabs.nl>, Ted Lemon <Ted.Lemon@nominum.com>, Mark Andrews <Mark_Andrews@isc.org>, bmanning@karoshi.com, Brian Dickson <briand@ca.afilias.info>, Joe Abley <jabley@ca.afilias.info>, Jelte Jansen <jelte@NLnetLabs.nl>, Andrew Sullivan <ajs@commandprompt.com>, Roy Arends <roy@nominet.org.uk>, bmanning@vacation.karoshi.com, Stephane Bortzmeyer <bortzmeyer@nic.fr>, Matthijs Mekking <matthijs@NLnetLabs.nl>, "Jesper G. Høy" <jesper@jhsoft.com>, Danny Mayer <mayer@gis.net>, Tony Finch <dot@dotat.at>, Edward Lewis <Ed.Lewis@neustar.biz>, Michael StJohns <mstjohns@comcast.net>, Ray.Bellis@nominet.org.uk, Eric Rescorla <ekr@networkresonance.com>, "David W. Hankins" <David_Hankins@isc.org>, Duane at e164 dot org <duane@e164.org>, Jim Fenton <fenton@cisco.com>, Paul Vixie <vixie@isc.org>, Masataka Ohta <mohta@necom830.hpcl.titech.ac.jp>
cc: DNSEXT WG <namedroppers@ops.ietf.org>, iesg@ietf.org
Subject: Kaminsky, Cache Poisoning, and Censorship
In-Reply-To: <48A3C436.7090301@e164.org>
Message-ID: <Pine.LNX.4.44.0808141417040.21350-100000@citation2.av8.net>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Scanned-By: MIMEDefang 2.64 on 66.92.146.20
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
[ Note: Post was moderated. ] > [ Moderators note: Post was moderated, either because it was posted by > a non-subscriber, or because it was over 20K. > With the massive amount of spam, it is easy to miss and therefore > delete relevant posts by non-subscribers. > Please fix your subscription addresses. ] The moderators note is false, and deceives the Working Group. I am a subscriber, and the post was not over 20K. The Chairs have chosen to censor messages which are relevant to WG business, but that are not exclusively technical. The type of messages they have said they will censor includes messages about RFC3979 compliance, messages about financial considerations for drafts, and messages concerning the integrity of the IETF process as described by RFC2026 section 6.5.1. In practice, they have blocked messages that merely oppose the unsubstantiated assertions of the BIND Cartel (ISC, Nomimum, UltraDNS, and Centergate Research) See http://www.av8.net/IETF-watch/DNSEXT/Management.html The assertion of personal attacks is a lie and a deception of the working group. In 2000, messages from Dr. Bernstein regarding DNS cache poisoning attacks was also censored. WG Chair Gudmundsson was involved in the censorship of those messages. WG Chair Olafur Gudmundsson has demanded that I "agree not to engage in personal attacks". Since I (Anderson) have never engaged in personal attacks, this demand is based on an implied fiction. It is known as a 'loaded question' fallacy. His demand is the same as the fallacious question 'have you stopped beating your wife?" As in the wife-beating fallacy, if I answer "no", then it seems as if I intend to continue making personal attacks, implying misconduct. If I answer "yes", it seems as if I concede to some past misconduct, also implying misconduct. WG Chair Gudmundsson was previously involved in the controversial AXFR-clarify draft promoted by the BIND Cartel and was involved in the deception of the DNSEXT WG over 1999-2002 through (at least) the censorship of Dr. Dan Bernstein, who opposed the draft. WG Chair Sullivan has specifically asserted that only technical messages can be posted to DNSEXT, denying that RFC3979 compliance, financial considerations, or discussion of the integrity of the process were appropriate subject matter. Recently appointed, WG Chair Andrew Sullivan has no relevant DNS experience, nor any long IETF experience. Sullivan has been a system administrator at Affilias for a few years, and was a protoge of Joe Abley, former ISC architech of DNS Anycast. Sullivan had also recently taken over the dubious IN-ADDR Required draft on DNSOP, renamed "Considerations for the use of DNS Reverse Mapping", but containing the same discredited claims as the IN-ADDR Required draft. This abuse has to stop. --Dean > On Mon, 11 Aug 2008, David Conrad wrote: > > > > > Only SSL can protect you here. > > > > As Dan Kaminsky points out: "SSL certs themselves are dependent on the > > DNS". > > Kaminsky is wrong. SSL uses DNS to obtain an IP address to connect to a > server, and then expects the server to produce a certificate, which the > client verifies. Spoofing DNS does not enable the attacker to obtain the > private key to the valid certificate. The DNS domain information placed > in a certificate merely allows the client to determine before > verification if it got the certificate it asked for. However the wrong > or fake certificate won't verify unless there is a fault in the > Certification Authority (this happened with MS some years ago). But a > spoofed DNS name going to a wrong server results in a failure to verify > the certificate. So SSL is NOT "dependent on DNS". > > Of course, if spoofed DNS sends the SSL connection to the wrong server, > a DOS attack still results since one didn't get to the correct server. > In that sense, everything a user does is dependent on DNS. > > But it is not the case that your bank information can be stolen by this > DNS attack, as Kaminsky seems to have told the mainstream press. > > --Dean > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000 -- to unsubscribe send a message to namedroppers-request@ops.ietf.org with the word 'unsubscribe' in a single line as the message text body. archive: <http://ops.ietf.org/lists/namedroppers/>
- How do we get the whole world to upgrade to DNSSE… Ben Laurie
- Re: How do we get the whole world to upgrade to D… Alex Bligh
- Re: How do we get the whole world to upgrade to D… David Conrad
- Re: How do we get the whole world to upgrade to D… bert hubert
- Re: How do we get the whole world to upgrade to D… Ted Lemon
- Re: How do we get the whole world to upgrade to D… bert hubert
- Re: How do we get the whole world to upgrade to D… David Conrad
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… bert hubert
- Re: How do we get the whole world to upgrade to D… bmanning
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… bert hubert
- Re: How do we get the whole world to upgrade to D… bert hubert
- Re: How do we get the whole world to upgrade to D… Brian Dickson
- Re: How do we get the whole world to upgrade to D… bmanning
- Re: How do we get the whole world to upgrade to D… Joe Abley
- Re: How do we get the whole world to upgrade to D… Jelte Jansen
- Re: How do we get the whole world to upgrade to D… Joe Abley
- Re: How do we get the whole world to upgrade to D… Joe Abley
- Re: How do we get the whole world to upgrade to D… Brian Dickson
- Re: How do we get the whole world to upgrade to D… David Conrad
- Re: How do we get the whole world to upgrade to D… bert hubert
- Re: How do we get the whole world to upgrade to D… Joe Abley
- Re: How do we get the whole world to upgrade to D… Andrew Sullivan
- Re: How do we get the whole world to upgrade to D… Jelte Jansen
- Re: How do we get the whole world to upgrade to D… Roy Arends
- Re: How do we get the whole world to upgrade to D… Joe Abley
- Re: How do we get the whole world to upgrade to D… bmanning
- Re: How do we get the whole world to upgrade to D… bmanning
- Re: How do we get the whole world to upgrade to D… Stephane Bortzmeyer
- Re: How do we get the whole world to upgrade to D… Brian Dickson
- Re: How do we get the whole world to upgrade to D… bmanning
- Re: How do we get the whole world to upgrade to D… Matthijs Mekking
- Re: How do we get the whole world to upgrade to D… David Conrad
- Re: How do we get the whole world to upgrade to D… bmanning
- RE: How do we get the whole world to upgrade to D… Jesper G. Høy
- RE: How do we get the whole world to upgrade to D… Alex Bligh
- RE: How do we get the whole world to upgrade to D… Jesper G. Høy
- RE: How do we get the whole world to upgrade to D… Alex Bligh
- RE: How do we get the whole world to upgrade to D… Jesper G. Høy
- Re: How do we get the whole world to upgrade to D… Jelte Jansen
- RE: How do we get the whole world to upgrade to D… Jesper G. Høy
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… David Conrad
- Re: How do we get the whole world to upgrade to D… Michael StJohns
- RE: How do we get the whole world to upgrade to D… Jesper G. Høy
- Re: How do we get the whole world to upgrade to D… David Conrad
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… Tony Finch
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… Edward Lewis
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… Dean Anderson
- Re: How do we get the whole world to upgrade to D… Ray.Bellis
- Re: How do we get the whole world to upgrade to D… Joe Abley
- Re: How do we get the whole world to upgrade to D… Eric Rescorla
- Re: How do we get the whole world to upgrade to D… Eric Rescorla
- Re: How do we get the whole world to upgrade to D… bmanning
- Re: How do we get the whole world to upgrade to D… David W. Hankins
- Re: How do we get the whole world to upgrade to D… Jim Fenton
- Re: How do we get the whole world to upgrade to D… Eric Rescorla
- Re: How do we get the whole world to upgrade to D… Eric Rescorla
- Re: How do we get the whole world to upgrade to D… Eric Rescorla
- Re: How do we get the whole world to upgrade to D… Ted Lemon
- Re: How do we get the whole world to upgrade to D… Ted Lemon
- Re: How do we get the whole world to upgrade to D… Duane at e164 dot org
- Re: How do we get the whole world to upgrade to D… Paul Vixie
- Re: How do we get the whole world to upgrade to D… David Conrad
- Re: How do we get the whole world to upgrade to D… Alex Bligh
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… Eric Rescorla
- Re: How do we get the whole world to upgrade to D… Mark Andrews
- Re: How do we get the whole world to upgrade to D… Duane at e164 dot org
- Re: Kaminsky, Cache Poisoning, and Censorship Brian Dickson
- A note of apology (Was: Kaminsky, Cache Poisoning… Andrew Sullivan
- Re: Kaminsky, Cache Poisoning, and Censorship Dean Anderson
- Kaminsky, Cache Poisoning, and Censorship Dean Anderson
- Re: A note of apology (Was: Kaminsky, Cache Poiso… Dean Anderson