Re: [OT: DNSCurve] Resolvers w/o key -> HMAC Proposal

Michael Sierchio <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
Matthew Dempsky wrote:
> On Sun, Dec 6, 2009 at 2:43 AM, Erwin Hoffmann <[email protected]> wrote:
>> d) [A] encrypts Query with Pubkey of [B] including the Nonce.
> 
> The main downside to this is that ... RSA ... requires much larger
> public-keys, takes a lot more time to encrypt and decrypt, and would
> expand the query size significantly.  You also don't get the benefit
> of being able to cache Diffie-Hellman computations.

I would say that one of the major advantages of dnscurve is that it
uses a form of identity-based encryption, in which the FQDN contains
an encoding of the public key.  Absolutely brilliant.

The current trust model still relies on a list of trusted root servers,
just as HTTPS works on the internet because browsers are shipped with
a trusted Root CA store.

-M
-- 
Michael Sierchio
+1 415 378 1182
PO Box 9036 Berkeley CA 94709 US
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.