Re: increasing DNS message entropy, a solution for NATs

Duane <duane@e164.org> Thu, 31 July 2008 08:00 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-namedroppers-archive-gleetwall6@core3.amsl.com
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 483EF28C22D; Thu, 31 Jul 2008 01:00:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.203
X-Spam-Level:
X-Spam-Status: No, score=-1.203 tagged_above=-999 required=5 tests=[AWL=-0.708, BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZpR9p0sbwyve; Thu, 31 Jul 2008 01:00:45 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 6492B28C1F4; Thu, 31 Jul 2008 01:00:45 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KOT0L-0008lQ-Iy for namedroppers-data@psg.com; Thu, 31 Jul 2008 07:55:21 +0000
Received: from [208.82.100.153] (helo=mail.aus-biz.com) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <duane@e164.org>) id 1KOT0H-0008kO-TA for namedroppers@ops.ietf.org; Thu, 31 Jul 2008 07:55:19 +0000
Received: from [192.168.100.244] (dsl-48-19.qld1.net.au [125.168.48.19]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mail.aus-biz.com (Postfix) with ESMTPSA id BEAACFF26C for <namedroppers@ops.ietf.org>; Thu, 31 Jul 2008 17:55:20 +1000 (EST)
Message-ID: <48916FCA.3040402@e164.org>
Date: Thu, 31 Jul 2008 17:54:50 +1000
From: Duane <duane@e164.org>
User-Agent: Thunderbird 2.0.0.16 (X11/20080724)
MIME-Version: 1.0
To: namedroppers@ops.ietf.org
Subject: Re: increasing DNS message entropy, a solution for NATs
References: <OF6B63EC19.5E0A6D58-ON8025748D.003A54A9-C125748D.003E1133@nominet.org.uk> <488517CE.6060404@necom830.hpcl.titech.ac.jp> <4891381B.1070400@links.org> <48913FA1.5010501@necom830.hpcl.titech.ac.jp> <B9A58880FC2AE5B486F366FF@Ximines.local>
In-Reply-To: <B9A58880FC2AE5B486F366FF@Ximines.local>
X-Enigmail-Version: 0.95.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

Alex Bligh wrote:

>> Because various NAT/PAT gateways put all the possible and impossible
>> modificaitons on certain, including DNS, packets that there is virtually
>> no directness expected.
> 
> I am guessing this is a very common SoHo configuration though.

Has anyone stopped to ask how much effort/emphasis should really be
spent trying to protect end users?

People perpetrating attacks on the internet still pay attention to the
principals of economics, that is getting the most benefit from the least
amount of work.

For what it's worth, I think the real focus here should be ISP
resolvers, not home users. Not to mention this should be a simpler
problem to solve for a number of reasons.

It seems to me that there is an excessive amount of attention being paid
to protect what is potentially 1 machine in most cases.

-- 

Best regards,
 Duane

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>