djbdns
[Top] [All Lists]

Re: djbdns-1.05-epoll + speedup patch

To: djbdns Mailing List <dns@list.cr.yp.to>
Subject: Re: djbdns-1.05-epoll + speedup patch
From: Charles Cazabon <dns@discworld.dyndns.org>
Date: Wed, 7 Mar 2007 09:57:55 -0600
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-djbdns@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list dns@list.cr.yp.to
In-reply-to: <20070307153920.e4674dxjvrwf6nm4@m.safari.iki.fi>
Mail-followup-to: djbdns Mailing List <dns@list.cr.yp.to>
Mailing-list: contact dns-help@list.cr.yp.to; run by ezmlm
References: <20070116171333.GA5674@m.safari.iki.fi> <20070222122129.GE3982@m.safari.iki.fi> <20070222162522.GG3982@m.safari.iki.fi> <20070304161657.qrytvzoi37inmj45@m.safari.iki.fi> <20070307143501.GA19509@codeblau.de> <20070307153920.e4674dxjvrwf6nm4@m.safari.iki.fi>
User-agent: Mutt/1.5.11
Sami Farin <safari-dns@safari.iki.fi> wrote:
> > 
> > surf is there for security reasons.  It is MEANT to take some time.
> > That's where its security comes from.
> 
> Well BIND seems to do better, according to this.
> http://www.lurhq.com/cachepoisoning.html

Eh?  Are you referring to that analysis of the PRNG in dnscache?

  The calprob output shows the randomness is still not perfect (in fact, it is
  slightly worse than BIND 9; 30% probability of a successful guess with a
  spoofing set size of 5000):
  [...]
  This is however offset by the fact that djbdns also generates random
  numbers for the source port of each query,
  [...]
  This forces the attacker to guess transaction ID and source port
  simultaneously. It is immensely difficult to succeed at such an attack,

dnscache is harder to poison than BIND 8 or BIND 9.

Charles
-- 
-----------------------------------------------------------------------
Charles Cazabon                              <dns@discworld.dyndns.org>
GPL'ed software available at:               http://pyropus.ca/software/
-----------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>