Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky

Andy Bradford <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Thus said Matthew Dempsky on Fri, 20 Feb 2009 15:47:47 PST:

> Is there anyone on this list other than Dean that thinks his arguments
> against Kevin's qmerge patch are at all credible? If not, I'm going to
> give  up on  replying to  his  emails until  I see  one with  concrete
> details of an attack against the patch. I'm tired of repeatedly asking
> him  to  specify  one,  and  his lack  of  logical  reasoning  is  too
> infuriating for me to continue without good cause.

This may  be a bit  rhetorical, but here  is Bruce Schneier's  model for
evaluating the security of any given solution:

1. What assets are you trying to protect?
2. What are the risks to those assets?
3. How well does the security solution mitigate those risks?
4. What other risks does the security solution cause?
5. What costs and trade-offs does the security solution impose?
Finally: Is the trade-off worth it?

What  is being  proposed is  some set  of patches  that presumably  make
dnscache more secure.

Here is another  set of questions, again by Bruce  Schneier, along those
same lines:

1. What problem does it solve? 
2. How well does it solve the problem? 
3. What new problems does it add? 
4. What are the economic and social costs? 
5. Given the above, is it worth the costs? 

So, where do the solutions proposed fit in here?

Andy
-- 
[-----------[system uptime]--------------------------------------------]
 12:13pm  up 25 min,  1 user,  load average: 1.34, 1.41, 1.18
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.