Re: High-speed cryptography
"Matthew Dempsky" <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Dec 11, 2008 at 3:35 PM, Paul Jarc <[email protected]> wrote: > So the client could take that as an indication that the > server doesn't support DNSCurve, and send a normal query instead. But > I don't see anything on dnscurve.org indicating that a client *should* > do that. A client certainly SHOULD NOT do that, otherwise the client is trivially vulnerable to man-in-the-middle downgrade attacks. In practice, the only time a domain name will contain a valid DNSCurve public key (i.e., the name will contain a component matching the regexp /uz5[0-9b-df-hj-np-z]{51}/) will be when that host is running a DNSCurve-aware DNS server.