Re: High-speed cryptography
Daryl Tester <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
(* Null reply-to set *) Matthew Dempsky wrote: > On Thu, Dec 11, 2008 at 3:35 PM, Paul Jarc <[email protected]> wrote: >> So the client could take that as an indication that the >> server doesn't support DNSCurve, and send a normal query instead. But >> I don't see anything on dnscurve.org indicating that a client *should* >> do that. > A client certainly SHOULD NOT do that, otherwise the client is > trivially vulnerable to man-in-the-middle downgrade attacks. <Thinking aloud here> What about an "upgrade" attack (essentially DoS)? What prevents someone from flooding a client with bogus DNSCurve NS responses, making the client think it should be talking to a DNSCurve server when it isn't? -- Regards, Daryl Tester "Oh Christmas tree, oh Christmas tree! From hell's heart I stab at thee." -- A very Kaaahn! Christmas