Re: DNSSEC, was Potentially Predatory Pre-Announcement of Possible Vaporware (zinq-djbdns-0.01)

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On 14 Nov 2008, John Levine wrote:

> >    When a signed root zone has actually been publicaly deployed, it
> > will be time to talk DNSSEC.
> 
> From what I see going on at ICANN, that's likely to be less than a year
> from now.  There's already some signed TLDs.

I suspect that once the NTIA learns of the vulnerabilities in DNSSEC and 
the new attacks possible with DNSSEC, that it will go back to the 
drawing board, and that people will probably use TCP DNS more 
extensively.

If theory isn't enough, the first 40Gbps attack emanating from the root
servers will probably be enough. Implementing DNSSEC on the roots opens
an easy way to bring down all 13 roots and all the anycast clones, and
that event would certainly be a flag day for the internet...

		--Dean


-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.