Re: DNSSEC, was Potentially Predatory Pre-Announcement of Possible Vaporware (zinq-djbdns-0.01)
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On 14 Nov 2008, John Levine wrote: > > When a signed root zone has actually been publicaly deployed, it > > will be time to talk DNSSEC. > > From what I see going on at ICANN, that's likely to be less than a year > from now. There's already some signed TLDs. I suspect that once the NTIA learns of the vulnerabilities in DNSSEC and the new attacks possible with DNSSEC, that it will go back to the drawing board, and that people will probably use TCP DNS more extensively. If theory isn't enough, the first 40Gbps attack emanating from the root servers will probably be enough. Implementing DNSSEC on the roots opens an easy way to bring down all 13 roots and all the anycast clones, and that event would certainly be a flag day for the internet... --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000