Re: High-speed cryptography

Daryl Tester <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
(* Null reply-to set *)

Matthew Dempsky wrote:

> On Thu, Dec 11, 2008 at 3:35 PM, Paul Jarc <[email protected]> wrote:

>> So the client could take that as an indication that the
>> server doesn't support DNSCurve, and send a normal query instead. But
>> I don't see anything on dnscurve.org indicating that a client *should*
>> do that.

> A client certainly SHOULD NOT do that, otherwise the client is
> trivially vulnerable to man-in-the-middle downgrade attacks.

<Thinking aloud here> What about an "upgrade" attack (essentially DoS)?
What prevents someone from flooding a client with bogus DNSCurve NS
responses, making the client think it should be talking to a DNSCurve
server when it isn't?


-- 
Regards,
  Daryl Tester

"Oh Christmas tree, oh Christmas tree!  From hell's heart I stab at thee."
  -- A very Kaaahn! Christmas
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.