5 ms·
Another reason to keep foundational protocols small. HTTP/2 has been around for more than a decade (including SPDY), and this is a first time this attack type s
by scrpl 3y ago
Another reason to keep foundational protocols small. HTTP/2 has been around for more than a decade (including SPDY), and this is a first time this attack type surfaced. I wonder what surprises HTTP/3 and QUIC hide...
- liveoneggs 3y agoQUIC didn't account for amplification attacks in its design and the people complaining about it were initially dismissed.
- cmeacham98 3y agoDNS is a small protocol and is abused by DDoS actors worldwide for relay attacks.
- scrpl 3y agoDNS is from 1983, give it some slack
- cmeacham98 3y agoThe point I'm trying to make is that "small" protocols aren't less likely to be DDoS vectors. Avoiding designing in DDoS relay/amplication vectors requires luck or intention, not just making the protocol small.
- scrpl 3y agoSmall, less complex protocols are inherently less likely to be insecure all things being equal, simply due to reduced attack surface. DNS was created for a different environment, at a time when security wasn't at forefront so it's not a good example of the opposite.
- Avamander 3y agoThis is such a strong claim I'd really appreciate something other than "smaller is better" Abuse and abuse vectors vary wildly in complexity, some complexity is certainly required exactly to avoid dumb bottlenecks if not vulnerabilities. So based on what are you saying something simple will inherently resist abuse better?
- baby_souffle 3y ago> Small, less complex protocols are inherently less likely to be insecure all things being equal, simply due to reduced attack surface. That feels intuitive in the "less code is less bugs is less security issues" sense but implies that "secure" and "can't be abused" are the same thing. Related? Sure. Same? No. Oddly enough, we probably could have prevented the replay/amplification dos attacks that use DNS by making DNS more complex / adding mutual authentication so it's not possible for A to request something that is then sent to B.
- LK5ZJwMwgBbHuVI 3y agoWe could have prevented the replay/amplification dos attacks that use DNS by making DNS use TCP. In practice though the only way to "fix" DNS that would've worked in the 80s would've probably been to require the request be padded to larger than the response...
- smallnix 3y agoBut TCP is way more complex
- LK5ZJwMwgBbHuVI 3y ago... yeah? I know? "In practice though the only way to "fix" DNS that would've worked in the 80s would've probably been to require the request be padded to larger than the response..." It's not as complex as some "mutual authentication" scheme though lmao
- aflag 3y agoI'm also from 1983 and I haven't been DDoSed
- kiitos 3y agoDNS is an enormous protocol, almost unmeasurably large.
- mcesch 3y agoThat's a bit overblown. There's a lot there and some of it conflicts with itself but it's not unmeasurably large by any means. It's a knowable protocol (and yes, I'm aware of the camel meme[1]). 1. https://powerdns.org/dns-camel/ https://powerdns.org/dns-camel/
- kiitos 3y agoQuiz: which RFCs do you need to know and implement to implement DNS?
- londons_explore 3y agoHTTP/2 is pretty small.