Re: Generic records and DKIM

Dean Anderson <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Wed, 18 Mar 2009, Matthew Dempsky wrote:

> On Wed, Mar 18, 2009 at 8:14 PM, Dean Anderson <[email protected]> wrote:
> > Dnscache has a 512byte limit on the packet size,
> 
> That's blatantly false.  dnscache accepts DNS packets over 512 bytes
> over TCP, exactly according to the spec.  With a patch, it also
> accepts larger (illegal) packets over UDP too.

Gee, talk about blatantly splitting hairs.  Its always funny how people
try to jump on the smallest thing.  Yes, I did mean UDP, and I know that
TCP handles larger responses. I'd suppose that should be obvious given
the discussion about TCP recently. But to be precise:

  Tinydns 1.05 won't send UDP packets larger than 512 bytes, doesn't
  support EDNSO in the tinydns authority server, and will fallback to 
  TCP on responses larger than 512 bytes. 

Matthew is Right. I concede that I didn't fully explain this.  Happy?

You might also want to look at the patch posted by Sami Farin on October
6th, 2008, and the subject thread 'Re: dnscache and oversized answers'.
There was some discussion of extending this to include larger 4096 byte
packets, but none of it is in the original 1.05 code. In dns_transmit.c,
you will find udpbuf to be 513 bytes. This patch(s) made
dns_transmit_get fall back to TCP for large packets, and handle ENDSO to
some extent (not completely). But they address only dnscache and some of
the programs like dnsq, and don't affect tinydns.


> > FYI, in response to another request, I'm putting together a page
> > on the 14 serious flaws with SPF identified to the IETF before approval
> > (15 or 16, I think if you include flaws discovered after SPF was
> > approved, including a DOS attack).
> 
> Terrific!  It sounds like this will be a long and difficult task that
> will take a lot of your time away from the mailing list, but don't
> worry, we'll understand.  Please take your time.

Wow, What a really spiteful thing to say. Is it that you don't care
about good engineering based on facts and critical analysis?  I
understand that attitude from the likes of Dave Crocker, William
Schlitt, John Levine, Paul Vixie et al who are selling the stuff and
some of those are selling CBE/spam services, too.  Those people simply
can't win technical arguments except by silencing their opponents
through dishonest means. But in science and engineering, facts are
paramount, and those who ignore and suppress the facts can't possibly
deliver on their technical promises. Their promises are just not
_possible_ and in this case violate the laws of information theory and
ultimately thermodynamics. 

The people (like yourself) still hoping they will deliver someday
despite the mounting evidence found in 15 years of failure, really ought
not be spiteful at the people (like myself) who noticed over 10 years
ago that the scammers didn't have the technical facts in the beginning.  
Relatively recently it was discovered that not only didn't the scammers
have the technical facts, but they had ulterior conflicting financial
motives in sending CBE/spam themselves, which they keep secret.  The
spam scammers are the Madoff's and AIG's of the antispam industry. But,
I guess that Madoff and AIG have their defenders, too---people who think
the they are innocent and good---people who won't look at the mounting
evidence to the contrary and are just angered by the evidence which
defies their belief in the goodness of the scammers.

It always amazes me, though. Have a good weekend.

		--Dean


-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.