Re: okay already

Dean Anderson <[email protected]> Mon, 22 Mar 2010 15:56:24 -0400 (EDT)
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Sat, 20 Mar 2010, Jason Haar wrote:

> On 03/20/2010 05:09 AM, Joe Baptista wrote:
> > I think the flaming and ranting is completely understandable. Comes
> > down to credibility. And right now the DNSSEC vs. DNScurve forces are
> > flaming and ranting at high speed to discredit DNScurve and Bernstein.
> Does anyone really believe DNScurve is ever going to become a true
> standard? 

It already is a defacto standard, being both well-defined and 
implemented.

However, as I've said before, securing DNS is a waste of time.  The
common case is out-of-path, and that is fixed with TCP. TCP has a _lot_
less overhead than either DNSSEC or DNSCurve.  The in-the-path case has
a lot more serious problems than DNS. 

It occurs to me that another effect of the King/Day/Kaminksy/Vixie
crack-to-make-forgery-consistent patch is that a slew of repeated
queries will be sent to different nameservers, not all of which might be
in the path.  By limiting to one query, a successfull interception
in-path to one nameserver, the attacker is guaranteed to get all the
queries outstanding.  The patch really does make cracking DNS consistent
and virtually undetectable.

> I think it will be too little - too late. DJB specializes in crypto
> and I'm absolutely sure DNScurve is better than DNSsec (leap of faith
> there), but I still think it doesn't matter.
> 
> DJB announced DNScurve around the time the design holes in DNS were
> getting some press, and I got all excited that he (or is that "He"? ;-)
> was about to release new code and there'd be a huge leap of interest
> worldwide and DNSsec might die. However, nothing appeared and the years
> rolled on - and DNSsec has government backing...
> 
> djbdns needs DNSsec support, otherwise one by one we will all be
> eventually told by our employers to replace it with one that does...

DJBDNS practically has DNSSEC support as an EDNSO-supporting,
non-verifying resolver. I think there is one bit that needs tracking for
this.  But DNSSEC verification opens a DDOS attack on the resolver, so
no one is rationally going to turn on DNSSEC verification.

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494