Re: [OT: DNSCurve] Resolvers w/o key -> HMAC Proposal
Michael Sierchio <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Matthew Dempsky wrote: > On Sun, Dec 6, 2009 at 2:43 AM, Erwin Hoffmann <[email protected]> wrote: >> d) [A] encrypts Query with Pubkey of [B] including the Nonce. > > The main downside to this is that ... RSA ... requires much larger > public-keys, takes a lot more time to encrypt and decrypt, and would > expand the query size significantly. You also don't get the benefit > of being able to cache Diffie-Hellman computations. I would say that one of the major advantages of dnscurve is that it uses a form of identity-based encryption, in which the FQDN contains an encoding of the public key. Absolutely brilliant. The current trust model still relies on a list of trusted root servers, just as HTTPS works on the internet because browsers are shipped with a trusted Root CA store. -M -- Michael Sierchio +1 415 378 1182 PO Box 9036 Berkeley CA 94709 US [email protected]