fanf: (Default)
[personal profile] fanf

[livejournal.com profile] beezari posted a copy of the leaked Matasano explanation of Kaminsky's new DNS attack. I believe the explanation isn't quite right. In his interview in the WIRED Threat Level blog Kaminsky mentions that the attack relies on CNAMEs. This means that it does not depend on glue nor on additional section processing, which is what Matasano described. I believe the real explanation is...

$ md5 <~/doc/kaminsky
ef96f2d9e973a36e825793ddeff48ae5

Date: 2008-07-23 20:46 (UTC)
gerald_duck: (duck and computer)
From: [personal profile] gerald_duck
The problem, as I've noted before, is that nobody's going to take a copy of that md5sum and you can easily edit your posting later. :-p

(The other problem is that md5 is no longer strong enough for this kind of thing.)

Date: 2008-07-23 21:14 (UTC)
From: [identity profile] ex-robhu.livejournal.com
Also, a blackhat probably poisoned your DNS server so you're not really viewing [livejournal.com profile] fanf's LJ ;-)

Date: 2008-07-24 10:20 (UTC)
simont: A picture of me in 2016 (Default)
From: [personal profile] simont
ef96f2d9e973a36e825793ddeff48ae5

[livejournal.com profile] fanf might be able to edit his LJ post, but he can't edit my comment. And if you reply to this comment, then I won't be able to edit it either (just in case you're worried we might be colluding).

Date: 2008-07-24 10:27 (UTC)
gerald_duck: (Innocence)
From: [personal profile] gerald_duck
Well, LJ annotates comments that get edited anyway.

On the other hand, if he deleted the comments, who would miss them? More useful to me is that I've now been e-mailed a copy of your reply to my comment. (-8

December 2025

S M T W T F S
 123456
78910111213
14151617181920
21222324 252627
28293031   

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated 2026-01-06 11:29
Powered by Dreamwidth Studios