6 ms·
DNS Cookies – Identify Related Network Flows
- codezero 7y agoSomeone linked this on a great thread about how dns can leak info. https://news.ycombinator.com/item?id=19828769 https://news.ycombinator.com/item?id=19828769 The parent thread is really interesting too. https://news.ycombinator.com/item?id=19828702 https://news.ycombinator.com/item?id=19828702
- SimeVidas 7y agoELI5 description?
- alex_anglin 7y agoLike HTTP cookies, but that users don't have control over since they're managed by network infrastructure.
- SimeVidas 7y agoI’m sorry, I really don’t know much about DNS. I still have many questions: Who sets it? How is it transmitted? Who can access it?
- bluejekyll 7y agoThe abstract from RFC 7873: —— DNS Cookies are a lightweight DNS transaction security mechanism that provides limited protection to DNS servers and clients against a variety of increasingly common denial-of-service and amplification/forgery or cache poisoning attacks by off-path attackers. DNS Cookies are tolerant of NAT, NAT-PT (Network Address Translation - Protocol Translation), and anycast and can be incrementally deployed. (Since DNS Cookies are only returned to the IP address from which they were originally received, they cannot be used to generally track Internet users.) —— At the end of the day, the data can really be any 8 byte set of data for the client part and up to 32 bytes for the server section. Which you could technically use to store anything you want (or the upstream resolver could). The linked article talks about using it for tracking users, which the abstract ironically says isn’t generally possible.
- pests 7y agoSpecifically the tracking is done here by randomly choosing IP addresses from a pool and correlating connection attempts to the resolved IP to the original DNS request. To quote the article: "With 2 IP addresses available in the pool, a 32-bit identifier requires 32 correlated connections. With 256 IP addresses, a 32-bit identifier requires only 4 correlated connections." IPv6 brings it down to just one.
- DanielDent 7y agoI published dnscookie.com in late 2015. I google "dns cookies" and a few other things terms, was surprised that the terminology appeared unused, and it seemed suitable for the concept I was describing. In May 2016, RFC 7873 was published which also uses the term "DNS cookies". These two things share a name but have different meanings. The naming collision is an unfortunate coincidence.
- bluejekyll 7y agoOh! Wow! That was a huge assumption on my part. I had assumed it was the afore mentioned RFC. That explains why the site make no mention of EDNS or OPT records. TIL...
- deleted 7y ago[deleted]
- DanielDent 7y agoIt's fun when you check the front page of HN and see your work :).
- codezero 7y agoI'm bummed it didn't stay there longer, not just for my own karma :)
- ble52 7y agoOK, now please tell me how do I block it?
- DanielDent 7y ago- Never allow any part of the computing systems you use to cache anything. - Insist that everything in your life exist in a state of being functionally pure & stateless. - Eliminate access to all sources of timing data. - Make sure that all tasks are completed in a pre-determined fixed amount of time regardless of resource contention. There are so many different side channel attacks, and the computing primitives & API choices we have been making for years make it challenging to build secure systems. Caches are very deeply embedded in the culture of how computing is done. Making tasks take longer than strictly necessary to avoid leaking information goes against our instincts to optimize system performance. It's going to take a lot of work and cost a lot of money to get software to a point where we aren't playing whack-a-mole with side channels. More pragmatically, the current implementation of this technique can be dealt with by being very conscious of how much data your DNS resolver(s) are leaking & being conscious of how large the anonymity set is of the userbase of your DNS resolver(s). If you limit DNS cache times and use blinding computation techniques to limit the identity information your DNS resolver has or retains about you, then DNS cookies can be largely mitigated. If you have faith that 1.1.1.1 is operated in the manner that Cloudflare claims, the measures they have taken go a long way to making DNS cookies unusable. I also pointed out some additional specific mitigations when I reported this issue to the Chromium team in October 2015: https://bugs.chromium.org/p/chromium/issues/detail?id=546733 https://bugs.chromium.org/p/chromium/issues/detail?id=546733
- feanaro 7y agoWhat if we designed the resolver to fetch many responses with the caching disabled and then caching all of them? In essence, force it to give you as many cookies as your desired anonymity set size and then sample this local store of cookies when calculating the response for the end client.
- DanielDent 7y ago
- phicoh 7y agoIn general, publicly visible DNS cookies are set by a DNS recursive resolver. Typically, multiple IP addresses share one recursive resolver. So it seems to me that a DNS cookie has strictly less information than an IP address.
- sairamkunala 7y agoIf this fingerprinting stays across say HTTP Proxies (or VPN/Tor network) and a regular network, this may be a way to track users especially for ad networks.