Shorter Details

Different analogy:

Before the attack:  A bad guy has a one in sixty five thousand chance of stealing your Internet connection, but he can only try once every couple of hours.

After the attack:  A bad guy has a one in sixty five thousand chance of stealing your Internet connection, and he can try a couple thousand times a second.

After the patch: A bad guy has a one in a couple hundred million, or even a couple billion chance of stealing your Internet connection.  He can still try to do so a couple thousand times a second, but it’s going to make a lot of noise.

Read the full entry »

Details

I thought it would be helpful, given things going on out there, to write up a guide to the attack that people could provide to their management. A lot of people are going to have to violate procedure and work extra hours. Maybe this will get a few pizzas approved 🙂

==

DNS is a system for, among other things, finding out what number to use when “calling” somebody on the Internet. Since there’s lots of people, in lots of places, there can’t just be one directory. Often, when you ask one server for a number, it tells you to go somewhere else. And when you go there, you might be sent to a third destination. This process — “recursion” — is repeated over and over, until you finally have the number for that name.

Of course, on the Internet, you aren’t really going anywhere. What’s actually happening is that you’re sending messages out, and receiving replies back. What prevents a bad guy from providing his own replies, with his own fake numbers for whatever you were looking for?

Not much — but not nothing.

DNS can be thought of as a race: A request is sent. A good guy and a bad guy both want to get their replies to be trusted. The good guy has an advantage: He sees the request, and inside of it he can find a secret number, somewhere between zero to sixty five thousand. The race is not won until someone crosses the finish line with the secret number, and while the bad guy could guess the number, he has only a 1/65,536 chance of guessing correctly. Worse, the winner of the race gets to say how long it will be until the next race! The numbers can work out that it would take months, even years for the bad guy to finally win a race.

Read the rest of this entry »

Here Comes The Cavalry

So, all the way back at the beginning of the year, I was astonished once I realized engineers from companies all around the world were flying out — on a few weeks notice, barely — to discuss how to fix my bug.

And now, with the bug finally public…everyone else is joining in.

First off, the ISP’s are on board!.  Andy Greenberg from Forbes went ahead and talked to the likes of AT&T, Time Warner Cable, and Cablevision, and while they’re not all patched up yet, they’re indeed working on it.  Let me take a moment to quote Time Warner here:

Time Warner Cable spokesman Alex Dudley responded, “We do have a solution to the DNS issue that we feel works for us, and we’re working on rolling it out as quickly as possible.” He added, “We have to make sure it works and that it doesn’t impact the system in any way.”

That was, in a nutshell, the very idea of this entire approach — to somehow give people a way to get these fixes out in a controlled manner, without forcing a panic.  If there’s one thing you do not want to be on fire, it’s your DNS server.  Nothing makes a network go wobbly faster.

Now, I’m not saying ISP’s don’t need to get (un)cracking.  The headline of Andy’s article is “Hackable Broadband Left Unpatched”, and with the notable and named exceptions of Comcast and Verizon, this is true.  But seeing Time Warner, and Earthlink, and even AT&T doing the right thing and actively investigating how to spread this fix out across their entire network is fantastic, even if it is not instantaneous.

Read the rest of this entry »

Just a quick note

1) Yes, I’m doing a webcast with Black Hat on the 24th 2) No, I’m not releasing the exploit early.

Now, let me be clear.  Oh wow, I wish I could drop the technical details on the 24th.  Did I really just sign up for a month of this?  But, no.  The webcast will be good.  The webcast will have interesting information.  You should indeed attend the webcast.  But I’m not screwing up everyone’s schedules with a huge “WHUPS JUST KIDDING”.  Details are being held until either August 6th at 11:15AM Pacific (thanks, Travis!), when I talk at the Black Hat Briefings.

Just a l’il while longer, guys.

Read the full entry »

Ow My Toe

So there’s been some skepticism about the DNS flaw.  I want to be clear:  It was richly deserved.  A “put up or shut up” mentality is critical to the survival of our industry.  It’s just too easy to make stuff up, if you can just wave away detractors with “I can’t prove it…it’d be UNSAFE.”

The danger from that statement is very tempting and very real.  Our credibility as an industry — ultimately, our ability to get bugs fixed — depends on that statement being called out as the bullsh*t that it is.

That being said:

It was my belief that this case was an exception to the rules.  Nobody reading this can know if I was right or not, because (almost) nobody knows the bug.  However, so far, things are going well:

1) Patches are out, from almost everybody. 2) People are installing them. 3) Nobody is panicking. 4) Nobody is being exploited.

Where I come from, that’s pretty damn cool.  But that could all have been accomplished…with no actual bug, just vague hand-wavey threats.

Read the rest of this entry »

An Astonishing Collaboration

Wow. It’s out. It’s finally, finally out.

Sweet!

So there’s a bug in DNS, the name-to-address mapping system at the core of most Internet services. DNS goes bad, every website goes bad, and every email goes…somewhere. Not where it was supposed to. You may have heard about this — the Wall Street Journal, the BBC, and some particularly important people are reporting on what’s been going on. Specifically:

1) It’s a bug in many platforms

2) It’s the exact same bug in many platforms (design bugs, they are a pain)

3) After an enormous and secret effort, we’ve got fixes for all major platforms, all out on the same day.

4) This has not happened before. Everything is genuinely under control.

I’m pretty proud of what we accomplished here. We got Windows. We got Cisco IOS. We got Nominum. We got BIND 9, and when we couldn’t get BIND 8, we got Yahoo, the biggest BIND 8 deployment we knew of, to publicly commit to abandoning it entirely.

Read the rest of this entry »