Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Workaround for DNS Fragmentation attacks #361

Open
CBonnell opened this issue Mar 31, 2022 · 3 comments
Open

Workaround for DNS Fragmentation attacks #361

CBonnell opened this issue Mar 31, 2022 · 3 comments

Comments

@CBonnell
Copy link
Member

No description provided.

@CBonnell CBonnell moved this to Backlog in Validation Aug 1, 2022
@CBonnell
Copy link
Member Author

CBonnell commented Aug 1, 2022

This item was discussed at the 2022-07-28 meeting.

There was no strong interest from the group to prioritize this item.

@wthayer
Copy link
Contributor

wthayer commented Nov 2, 2023

I believe this was discussed on MDSP in 2018: https://groups.google.com/g/mozilla.dev.security.policy/c/emREqhAZ3nM/m/lx8Rp3Q7BwAJ

The thread implies that multi-perspective validation at least partially mitigates this attack. @ryancdickson is going to confirm with the folks at Princeton before we close this issue.

@ChristopherRC
Copy link
Contributor

Confirmed with Princeton. Yes, MPIC helps address this issue.

“As discussed in slide 34 of the deck linked in that thread (https://i.blackhat.com/eu-18/Thu-Dec-6/eu-18-Heftrig-Off-Path-Attacks-Against-PKI.pdf) the authors of this work actually developed a very similar system (known as DOMAIN VALIDATION++) designed to mitigate these attack which also uses multiple network perspectives to perform domain validation. At a conceptual level the current MPIC push is nearly identical to DOMAIN VALIDATION++ and also inherits many of the same protections that mitigate this attack.”

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Backlog
Development

No branches or pull requests

3 participants