skip to content

Told that source-port randomisation makes DNS cache poisoning infeasible, how do you answer?

level: seniorimportance: should knowfreq 41%

answer

  1. concede the number, reject the conclusion
  2. does the randomness reach the wire
  3. the objective, not the technique
  4. one login versus hours of flood
  5. class predicts route, not capability

basics

~20 s

Concede the arithmetic, reject the conclusion. The objective is to be believed as the authority for a name, and that is on sale far cheaper at the registrar, where changing the delegation beats no entropy.

solid answer

~50 s

Two moves. First, agree that against a resolver whose per-query port randomisation genuinely reaches the wire, a single opportunistic race is a one-in-tens-of-thousands shot, and a serious campaign needs sustained multi-gigabit traffic plus a way to force repeated lookups. Then point out that the arithmetic only holds if the randomness survives the path — a NAT rewriting ports into a narrow range or a forwarder reusing one socket puts you back near 2^16. Second, and more importantly, reframe the objective. The attacker does not want to win a race; they want traffic for a name to go where they say. Taking over the account that controls the domain's delegation delivers exactly that, permanently, to every resolver on the internet, for the price of one password reset on a recovery mailbox. Defending the technique is not the same as defending the objective.

go deeper

for a junior

Know that a hardened resolver makes a forged answer very unlikely, and that this says nothing about other ways an attacker could become the answer for a name.

for a middle

Explain the entropy arithmetic well enough to agree with it, and name at least one way the randomisation can be undone on the path out.

for a senior

Demonstrate the reframe under pressure: separate the technique from the objective, enumerate the routes to that objective and price them, and say which one an attacker actually buys.

for a principal

Own the consequence for spend: a control that only raises the cost of the most expensive route leaves the adversary's total cost unchanged, which is an argument about where money goes, not about DNS.

## Why the claim is half right The arithmetic behind "infeasible" is sound as far as it goes. A resolver that draws a random ephemeral port per query and a random 16-bit message ID presents something like four billion combinations, and the guessing window closes when the genuine answer arrives. Landing a hundred thousand distinct guesses inside a hundred-millisecond window is a one-in-tens-of-thousands shot, and each shot needs a fresh outstanding query. Multiply that out and a campaign means hours of sustained spoofed-source flood aimed at one resolver. Nobody should claim that is easy. What makes the conclusion wrong is that it defends a **technique** and then declares the **objective** defended. ## Attack the assumption first Before leaving the technique, test whether the entropy you are being credited with actually exists on the wire: - Is there a NAT device or middlebox in front of the resolver's egress? If it rewrites source ports into a small or sequential range, the resolver's random choice is overwritten and the port term drops towards zero. - Do branch offices or endpoint stubs forward through something that reuses a single socket? The weakest hop sets the real entropy, not the strongest. - Is the ID generator actually random, or a counter? Any one of those turns 2^32 into something nearer 2^16, and at 2^16 a single window's worth of guesses is not a lottery ticket. "We randomise" is a statement about configuration; the question is what leaves the building. ## Then reframe the objective Ask what the attacker is buying. It is not the thrill of a matched message ID. It is: *when anyone looks up this name, they are handed an address I control.* Enumerate the routes to that outcome and price each: | Route | What it costs | What it yields | |---|---|---| | Race the resolver | hours of multi-gigabit spoofed traffic, a way to force repeated lookups, luck | one poisoned record, in one resolver, until it expires | | Take the account that controls the delegation | one credential, or one password reset against a recovery mailbox | authority for the entire zone, on every resolver worldwide, until someone notices | The second row is not an exotic idea; it is the ordinary way names change hands. Domain records are administered through a web account. Whoever can sign in there can repoint the nameservers for the zone, and from that moment they are the authority for the name — not by forging an answer, but by being handed the delegation legitimately. Resolvers worldwide follow it as the correct answer, because it is the correct answer. And the blast radius is not one record in one resolver. It is every name in the zone, everywhere, and it persists until a human notices and unwinds it. ## What the adversary class predicts The route taken tracks the crew, and this is worth saying explicitly because "nation-state" is usually treated as a synonym for "can do anything": - A **criminal with a revenue motive** takes the cheapest reliable path and does not care about elegance. That is the account, almost always. Sustained gigabit floods for hours at one campus resolver is a terrible business decision when a login exists. - A **state-aligned crew** has bandwidth, time and no revenue target, so the race is *affordable* to them. But affordability is not preference: they too generally prefer control that does not require sustained noisy traffic. Where the race wins for them is when the objective is narrow and the account route is closed or unattractive — a single resolver population they want to influence without a public, durable change to the zone's delegation that everyone can look up. So "they are a nation-state" does not predict that they will race the resolver. It predicts that they *could*, and that the cheap route being closed does not end the conversation. ## How to say it in an interview Do not argue the arithmetic — you will lose, because the arithmetic is fine. Say: the number is right for one opportunistic race, and it is only right if the randomisation survives NAT and forwarding, which I would check. But the number defends a technique, and what we care about is the objective. The same objective has a much lower purchase price at the account that controls the delegation, so a control that only raises the cost of the race has not moved the attacker's total cost at all. That answer shows the thing the question is testing: that you price an adversary's options, not a single technique's difficulty.

  • What changes if you are told the crew is state-aligned rather than criminal?
    Affordability, not preference. A state-aligned crew can fund hours of high-rate traffic and long timelines, so the race stops being ruled out on cost. They still generally prefer control that is not noisy and not durable in public records. So the class tells you the cheap route being closed does not end the threat — not that they will choose the expensive one.
  • Give one thing you would check before accepting that a resolver's port randomisation is real.
    Whether anything between the resolver and the internet rewrites source ports. A NAT that maps into a narrow or sequential range replaces the random choice with a predictable one, and the attacker faces the rewritten value, not the chosen one. Forwarding resolvers that reuse a single socket have the same effect on the hop that matters.
  • Why is a delegation change so much worse than one poisoned record?
    Scope and persistence. A won race puts one wrong record into one resolver until it expires. A changed delegation makes the attacker authoritative for the whole zone, so every resolver on the internet gets the wrong answer for every name in it, and the state persists until a person notices and reverses the change at the registry.

Reinforcing the back door is real work, but the burglar is at the estate agent's office asking for the keys, and they will be given them.

saying these in an interview costs you the question

  • Accepts infeasibility and stops there
  • Defends the technique and calls the objective defended
  • Assumes configured randomisation always reaches the wire
  • Says nation-state means they will run the hardest attack
  • Compares only techniques, never their purchase price

context