Re: High-speed cryptography
Daryl Tester <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Matthew Dempsky wrote: > On Thu, Dec 11, 2008 at 12:09 PM, Daryl Tester > <[email protected]> wrote: >> e.g. I'm not sure what should happen if the content server is "unsigned". > What do you mean? The above question was taken slightly out of context - I *really* wasn't kidding when I said I need to go back and reread the literature. My mental model of DNSCurve is incomplete, shaky, and has lots of unanswered (and quite possibly inaccurate) questions. > A DNSCurve client knows whether or not a server is DNSCurve-aware by > inspecting the NS record name. For example: How does it know the name server is DNSCurve aware? What distinguishes uz5xgm1kx1zj8xsh51zp315k0rw7dcsgyxqh2sl7g8tjg25ltcvhyw.nytimes.com from someoneshonkinghugenameservername.nytimes.com? > It only sends DNSCurve queries to DNSCurve-aware servers, and falls back > to standard DNS queries for non-DNSCurve-aware servers. Are DNSCurve content servers allowed to pass out "traditional" (non-signed) answers? From this, could it be possible for the protocol to be subverted? (These are rhetorical questions, and I really don't want them answered - it aids me building my mental model figuring out the answers to these myself). -- Regards, Daryl Tester "Oh Christmas tree, oh Christmas tree! From hell's heart I stab at thee." -- A very Kaaahn! Christmas