[dns-operations] Subverting BIND's SRTT Algorithm Derandomizing NS Selection

Paul Ferguson fergie at people.ops-trust.net
Tue May 6 18:28:03 UTC 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On 5/6/2014 11:05 AM, Evan Hunt wrote:

> On Tue, May 06, 2014 at 10:56:03AM -0700, Paul Ferguson wrote:
>> "ISC plans to address this deficiency by reimplementing the SRTT 
>> algorithm in future maintenance releases of the BIND 9 code."
>> 
>> Was this reimplementation done, and if so, what version was it 
>> implemented?
> 
> Not yet.
> 

Thank you for the response.

- - ferg

- -- 
Paul Ferguson
VP Threat Intelligence, IID
PGP Public Key ID: 0x54DC85B2
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (MingW32)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iF4EAREIAAYFAlNpKbMACgkQKJasdVTchbKeAQEAiHJ7Seylu8lNfnIOMyQuAt4L
6Ko20ezbDffSgIZboigBAMAnHf7JkFOnRCn3GfD8hWZ+UYRaGO9nacPYskb3wu4V
=YpRr
-----END PGP SIGNATURE-----



More information about the dns-operations mailing list