Kaminsky's DNS hack
2008-07-23 19:20
beezari posted a copy of the leaked Matasano explanation of Kaminsky's new DNS attack. I believe the explanation isn't quite right. In his interview in the WIRED Threat Level blog Kaminsky mentions that the attack relies on CNAMEs. This means that it does not depend on glue nor on additional section processing, which is what Matasano described. I believe the real explanation is...
$ md5 <~/doc/kaminsky ef96f2d9e973a36e825793ddeff48ae5
no subject
Date: 2008-07-23 20:46 (UTC)(The other problem is that md5 is no longer strong enough for this kind of thing.)
no subject
Date: 2008-07-23 21:14 (UTC)no subject
Date: 2008-07-24 10:20 (UTC)ef96f2d9e973a36e825793ddeff48ae5no subject
Date: 2008-07-24 10:27 (UTC)On the other hand, if he deleted the comments, who would miss them? More useful to me is that I've now been e-mailed a copy of your reply to my comment. (-8