Re: managed DNS daydream continues

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Fri, 12 Sep 2008, Michael Sierchio wrote:

> Dean Anderson wrote:
> 
> > The point is that there is only two categories:  One category of attack
> > that can come from anywhere, and the other category of attack can only
> > come from the middle.  TCP eliminates the first category, so no further
> > effort is needed to eliminate that category. TLS, properly verified,
> > completely eliminates the second category, so no further effort is
> > needed to eliminate that category.  All done. No more changes to DNS are
> > needed. 
> 
> A TCP-based DNS and/or TLS-based DNS will not scale, will not provide
> the performance expected of DNS.  Period.  Most DNS responses occur in
> the span of time in which a three-way handshake for TCP would still be
> occurring.

If you think this is true, DNSSEC won't scale either.  Most 3 way
handshakes can occur and an unsigned packet transmitted before an 8Kb
response can be sent and cryptographically verified.

BTW, I'm not advocating TLS for DNS:

Offlist from another participant:
> So you are in favor of DNS over TCP+TLS.

Not exactly. I'm in favor of DNS over UDP to caches that use TCP to the
world, or else DNS over TCP to caches that use TCP.

Protocols that need security should use TLS. DNS itself doesn't need
TLS, and doen't need a high level of security. In the second category
(MITM) of attack, TLS is necessary and sufficient to handle the case
where DNS doen't give the right answer, and TLS is necessary to handle
the case where DNS does give the right answer, but there is still a
MITM.

In the first category, DNS over TCP is enough to be secure against DNS
attacks from anywhere not in the middle.  Where one isn't concerned
about a MITM attack, either the information isn't that sensitive and/or
speed is more important than security. For the most extreme case that
speed is the most important, UDP may be sufficient even with the known
limitations.

This is where I see DNS going.  There are some issues to be resolved
with lots of (possibly long) TCP connections in most implementations of
DNS servers. However, this is an implementation issue that can be
resolved.


		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.