Re: Potentially Predatory Pre-Announcement of Possible Vaporware (zinq-djbdns-0.01)

Bernd Plagge <[email protected]>
Newsgroups gmane.network.djbdns
Organization First Choice Internet Ltd.
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Heated arguments flying forward and backward.

I've been using tinydns for over 8 years. 
In the past I also used qmail but it became too painful to compare the
various patches and to combine them. I'm now using Courier which is a
very complete package and there are Debian packages available for it
(in the past I built Debian packages myself).

You're on the right track whatever the purists are saying.
All major Linux installations are using package managers (no insult
intended, I'm talking about installation figures) and for this reason
all commonly used software is provided as RPM and DEB package.

I don't know much about rpm's but here are some facts about deb
packages:
- - you can build several deb packages from one source package
- - to build a deb package it is best to use autoconf etc with proper
  support for various system paths ($prefix etc)
  (that means if a package comes with autoconf, automake it is
  easy to built deb package)

Personally I don't think that DNSSEC will come - at least not worldwide
- - because countries will just not accept that the US is controlling the
DNS system. This, however, is a personel opinion and as the US has
decided that .mil and .gov domains have to use DNSSEC there is little
argument about the fact that it would be beneficial for tinydns to be
able to support this.
This does not mean that everybody has to use it. The inclusion of
DNSSEC could be handled by a configuration variable. That way you
compile without DNSSEC support if you don't need it.

Also, I checked DNSCurve but it seems that there is no implementation
for tinydns yet. I may be worth to contact the DNSCurve guys to obtain
some more information.
A working DNSCurve implementation for tinydns as well as the
availability of suitable library routines to be used for other DNS
resolvers is an absolute necessity to promote an alternative to DNSSEC.

One of the main arguments for DNSSEC brought forward by ISC is that
lot's of time (and money) was spent on DNSSEC development AND that
there is no alternative.
Nobody cares about the money because spent is spent and you won't get
any cent back regardless whether you use it or not.
But it is important to have an alternative. If implementation costs of
the (DNSCurve) alternative are much lower and it is at least as secure
as DNSSEC then you also got a practical argument against DNSSEC.

I'm quite willing to test a DNSCurve implementation as soon as it
becomes available.

BTW, djbdns tinydns does not support IPV6 but there are patches to add
IPV6 support to tindyns and to uscpi-tcp. Did you include this?

Regards,
Bernd



On Thu, 13 Nov 2008 13:37:33 -0600
"Mark Johnson" <[email protected]> wrote:

> On Thu, Nov 13, 2008 at 12:54 PM, Laurent Bercot <[email protected]> wrote:
> >  What was it motivated by?
> >  Look at the obvious coding style differences between autoconf and
> > djbdns. Since you're working on djbware, I think it's safe to assume
> > you like DJB's coding style. Why then succumb to the bloated side and
> > create some unholy hybrid?
> 
>     Bloated?  The autotooled version has *less* code.  I don't see
> what the build system has to do with coding style.  The generated
> Makefile produces the same executables as Dan's Makefile would.
> 
> >  As for DNSSEC: for heaven's sake, please, no.
> >  DNSSEC does not work. DNSSEC will not work. With all the resources
> > that the ISC, and AFAIK the US government, have invested into DNSSEC,
> > it would be working *now* if it was meant to work.
> >  But it's not. It's flawed by design.
> 
>     When a signed root zone has actually been publicaly deployed, it
> will be time to talk DNSSEC.
> 
> >  DJB's policy is: do not implement or use things that are flawed by
> > design.
> >  This policy has kept the code clean, secure and small. Please do not
> > go against it, no matter how much political pressure you're submitted
> > to.
> 
>     I'm not DJB.
> 
> >  It's okay to not implement something that can only work in the mind
> > of a few people, no matter how influential those people may be.
> 
>     If something will make the Internet a better place, I may support
> it.  I am not convinced this will be the case for DNSSEC.  I am also
> not convinced that this will *not* be the case.  With adequate thrust
> and sufficient directional control, pigs can be made to fly.
>     You seem to have mistaken me for somebody important enough to
> pressure politically.  This is not the case.


- -- 
プラゲ ベェアント - Bernd Plagge
ファースト・チョイス・インターネット(有)
First Choice Internet Ltd., Tokyo
Tel. 03-4500-7799
Fax. 03-4400-3723
mail: [email protected]
url: http://www.choicenet.ne.jp
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkkcwDAACgkQpYU8M8PbPV7SzwCfYwXa7n8cTwrAF8NNpDjByewg
9AUAoJN2RcEo4k8LuW6pttw3bKgenKS5
=aBcs
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.