Re: okay already
Dean Anderson <[email protected]> Mon, 22 Mar 2010 15:56:24 -0400 (EDT)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 20 Mar 2010, Jason Haar wrote: > On 03/20/2010 05:09 AM, Joe Baptista wrote: > > I think the flaming and ranting is completely understandable. Comes > > down to credibility. And right now the DNSSEC vs. DNScurve forces are > > flaming and ranting at high speed to discredit DNScurve and Bernstein. > Does anyone really believe DNScurve is ever going to become a true > standard? It already is a defacto standard, being both well-defined and implemented. However, as I've said before, securing DNS is a waste of time. The common case is out-of-path, and that is fixed with TCP. TCP has a _lot_ less overhead than either DNSSEC or DNSCurve. The in-the-path case has a lot more serious problems than DNS. It occurs to me that another effect of the King/Day/Kaminksy/Vixie crack-to-make-forgery-consistent patch is that a slew of repeated queries will be sent to different nameservers, not all of which might be in the path. By limiting to one query, a successfull interception in-path to one nameserver, the attacker is guaranteed to get all the queries outstanding. The patch really does make cracking DNS consistent and virtually undetectable. > I think it will be too little - too late. DJB specializes in crypto > and I'm absolutely sure DNScurve is better than DNSsec (leap of faith > there), but I still think it doesn't matter. > > DJB announced DNScurve around the time the design holes in DNS were > getting some press, and I got all excited that he (or is that "He"? ;-) > was about to release new code and there'd be a huge leap of interest > worldwide and DNSsec might die. However, nothing appeared and the years > rolled on - and DNSsec has government backing... > > djbdns needs DNSsec support, otherwise one by one we will all be > eventually told by our employers to replace it with one that does... DJBDNS practically has DNSSEC support as an EDNSO-supporting, non-verifying resolver. I think there is one bit that needs tracking for this. But DNSSEC verification opens a DDOS attack on the resolver, so no one is rationally going to turn on DNSSEC verification. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494