Re: XQID (Re: Forgery Resistance phase #2 )
Jelte Jansen <jelte@NLnetLabs.nl> Wed, 30 July 2008 19:36 UTC
Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-namedroppers-archive-gleetwall6@core3.amsl.com
Delivered-To: ietfarch-namedroppers-archive-gleetwall6@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 735033A68D8; Wed, 30 Jul 2008 12:36:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.288
X-Spam-Level:
X-Spam-Status: No, score=-102.288 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HOST_MISMATCH_NET=0.311, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CwJrrlyzmtbz; Wed, 30 Jul 2008 12:36:29 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 54CA93A68B0; Wed, 30 Jul 2008 12:36:29 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KOHLk-000CC9-Lx for namedroppers-data@psg.com; Wed, 30 Jul 2008 19:28:40 +0000
Received: from [2001:7b8:206:1:7200:ff:fe00:28e3] (helo=sol.nlnetlabs.nl) by psg.com with esmtp (Exim 4.69 (FreeBSD)) (envelope-from <jelte@NLnetLabs.nl>) id 1KOHLf-000CBD-G0 for namedroppers@ops.ietf.org; Wed, 30 Jul 2008 19:28:38 +0000
Received: from jelte (vhe-520087.sshn.net [195.169.221.157]) by sol.nlnetlabs.nl (Postfix) with ESMTP id B4BF213002B; Wed, 30 Jul 2008 21:28:34 +0200 (CEST)
Received: from [192.168.8.11] (dragon [192.168.8.11]) by jelte (Postfix) with ESMTP id 8E8C1CF982; Wed, 30 Jul 2008 21:28:34 +0200 (CEST)
Message-ID: <4890C0E3.406@NLnetLabs.nl>
Date: Wed, 30 Jul 2008 21:28:35 +0200
From: Jelte Jansen <jelte@NLnetLabs.nl>
User-Agent: Thunderbird 2.0.0.16 (X11/20080724)
MIME-Version: 1.0
To: Paul Vixie <vixie@isc.org>
Cc: namedroppers@ops.ietf.org
Subject: Re: XQID (Re: Forgery Resistance phase #2 )
References: <200807281555.m6SFsxAO021711@stora.ogud.com> <027b01c8f17e$f99b0a80$ecd11f80$@com> <1135.1217352731@nsa.vix.com> <4890AE49.7040006@NLnetLabs.nl> <71458.1217444406@nsa.vix.com>
In-Reply-To: <71458.1217444406@nsa.vix.com>
X-Enigmail-Version: 0.95.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Paul Vixie wrote: > > though i'm beginning to realize that the > requirement should be phrased as "each query transaction must be protected > by XYZ bits of high quality random entropy, which can be reached using any > combination of udp port number, query ID, DNS 0x20 bits, PING, or repeated > queries". XYZ is probably about 50 if we want to rule out guessing > attacks. > I'm actually not too sure of whether a 'mix and match to your hearts content' approach is what we should be trying to achieve here. Although that might make debugging problems so insanely difficult that switching to DNSSEC will be a relief :) I do have two questions, that probably go for all the add-entropy proposals; 1. Do all recursive servers even have access to enough entropy? This might not be a problem at all, or extra entropy could be arranged for busy ones, but it might be worth thinking about in advance. For that matter, what about dos attacks where the entropy pool itself is attacked, is that possible? What would happen then? 2. Is it feasible to require (as a deployment consideration or otherwise) that in setups where there might be multiple implementations pretending to be one server, all implementations should have the exact same feature set? Would we even want that? Jelte -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFIkMDi4nZCKsdOncURAlTdAKDU19655aBuQq/NGIL9D/3PqIinUgCeKT34 I6CflhDt2VWTFZnUslBhYOs= =QGMD -----END PGP SIGNATURE----- -- to unsubscribe send a message to namedroppers-request@ops.ietf.org with the word 'unsubscribe' in a single line as the message text body. archive: <http://ops.ietf.org/lists/namedroppers/>
- Re: Forgery Resistance phase #2 Paul Hoffman
- Re: Forgery Resistance phase #2 Olafur Gudmundsson
- Forgery Resistance phase #2 Ólafur Guðmundsson /DNSEXT chair
- Re: Forgery Resistance phase #2 Alex Bligh
- RE: Forgery Resistance phase #2 Jesper G. Høy
- XQID (Re: Forgery Resistance phase #2 ) Paul Vixie
- Re: XQID (Re: Forgery Resistance phase #2 ) Jelte Jansen
- Re: XQID (Re: Forgery Resistance phase #2 ) Paul Vixie
- Re: XQID (Re: Forgery Resistance phase #2 ) Jelte Jansen
- Re: XQID (Re: Forgery Resistance phase #2 ) Paul Vixie
- Re: XQID (Re: Forgery Resistance phase #2 ) bert hubert