Re: High-speed cryptography

Daryl Tester <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Matthew Dempsky wrote:

> On Thu, Dec 11, 2008 at 12:09 PM, Daryl Tester
> <[email protected]> wrote:

>> e.g. I'm not sure what should happen if the content server is "unsigned".

> What do you mean?

The above question was taken slightly out of context - I *really* wasn't
kidding when I said I need to go back and reread the literature.  My mental
model of DNSCurve is incomplete, shaky, and has lots of unanswered (and
quite possibly inaccurate) questions.

> A DNSCurve client knows whether or not a server is DNSCurve-aware by
> inspecting the NS record name.

For example: How does it know the name server is DNSCurve aware?  What
distinguishes uz5xgm1kx1zj8xsh51zp315k0rw7dcsgyxqh2sl7g8tjg25ltcvhyw.nytimes.com
from someoneshonkinghugenameservername.nytimes.com?

> It only sends DNSCurve queries to DNSCurve-aware servers, and falls back
> to standard DNS queries for non-DNSCurve-aware servers.

Are DNSCurve content servers allowed to pass out "traditional" (non-signed)
answers?  From this, could it be possible for the protocol to be subverted?  

(These are rhetorical questions, and I really don't want them answered - it
aids me building my mental model figuring out the answers to these myself).


-- 
Regards,
  Daryl Tester

"Oh Christmas tree, oh Christmas tree!  From hell's heart I stab at thee."
  -- A very Kaaahn! Christmas
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.