5 ms·
I'm sorry if I miss it, but no protocol in this millennium should be without mitigation for denial of service. DJB's curveprotect uses fixed sized packages (re
by FullyFunctional 5y ago
I'm sorry if I miss it, but no protocol in this millennium should be without mitigation for denial of service. DJB's curveprotect uses fixed sized packages (refusing small ones) to kill amplification attacks. I wonder if they considered such issues.
- Arathorn 5y agoiirc curveprotect is effectively a replacement for TCP which uses EC crypto to encrypt each packet individually, and protects against DoS by each packet being cryptographically authenticated. Ultra low bandwidth Matrix does the same thing but using Noise instead.
- FullyFunctional 5y agoNo, that doesn't protect again amplification attacks by itself. Quoting https://curvecp.org/availability.html https://curvecp.org/availability.html: Blind amplification Some protocols allow attackers anywhere on the Internet to generate a packet that will trigger a much larger outgoing packet from the server to a victim address selected by the attacker. The issue here isn't the availability of that protocol; the issue is that the protocol is amplifying the attacker's resources, damaging availability for the rest of the Internet. The worst offender at the moment is DNSSEC, which has set up a remote-controlled machine-gun pool containing more than 2000 servers with amplification factors between 30 and 95 and with an overall outgoing attack capacity estimated to be close to 50 gigabits per second. With CurveCP, the first incoming packet from the client is padded so that it is as large as the outgoing packet from the server. If this padding is missing, the server won't respond. Subsequent packets from the client need to repeat server cookies and can't be generated blindly.
- Arathorn 5y agoRight, understood - it’s the same reason that QUIC pads incoming packets to MTU. We deliberately don’t do this on ultra-low-bandwidth Matrix (as described in the original post) to save bits, so you would typically use it on a private network. For low-bandwidth matrix we use DTLS rather than Noise, which gets this right.