Re: High-speed cryptography
[email protected] (Paul Jarc)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | What did you have in mind? A short, blunt, human pyramid? |
| Message-ID | <[email protected]> |
Daryl Tester <[email protected]> wrote: > <Thinking aloud here> What about an "upgrade" attack (essentially DoS)? > What prevents someone from flooding a client with bogus DNSCurve NS > responses, making the client think it should be talking to a DNSCurve > server when it isn't? If the queries to the parent server are unencrypted, that's possible, but rather difficult, assuming the client randomizes query IDs and source ports. It's no different from any other forgery attack today. paul