Re: okay already

Dean Anderson <[email protected]> Mon, 22 Mar 2010 15:44:57 -0400 (EDT)
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On Sat, 20 Mar 2010, Christopher Chan wrote:

> Jason Haar wrote:
> > On 03/20/2010 05:09 AM, Joe Baptista wrote:
> >> I think the flaming and ranting is completely understandable. Comes
> >> down to credibility. And right now the DNSSEC vs. DNScurve forces are
> >> flaming and ranting at high speed to discredit DNScurve and Bernstein.
> > Does anyone really believe DNScurve is ever going to become a true
> > standard? I think it will be too little - too late. DJB specializes in
> > crypto and I'm absolutely sure DNScurve is better than DNSsec (leap of
> > faith there), but I still think it doesn't matter.
> > 
> > DJB announced DNScurve around the time the design holes in DNS were
> > getting some press, and I got all excited that he (or is that "He"? ;-)
> > was about to release new code and there'd be a huge leap of interest
> > worldwide and DNSsec might die. However, nothing appeared and the years
> > rolled on - and DNSsec has government backing...
> 
> /me blinks. DNSSec does?

No. While the Vixie/Cerf cartel thinks it can sign the roots in July,
the government is actually changing its policy from non-interference to
oversight.  I'm getting through to all the right people, I think.

> > djbdns needs DNSsec support, otherwise one by one we will all be
> > eventually told by our employers to replace it with one that does...
> > 
> 
> HAHAhaha. I'm so worried. Running tinydns for bradbury.edu.hk and the
> clueless replacement at IAS will not even know what you are talking
> about.

Well, even if the roots are signed, any resolver can disable DNSSEC.  
The problem isn't that one is forced to use DNSSEC, the problem is that
abusers can use root and TLD nameservers in DDoS attacks that are
impossible to mitigate; that the 512 bits keys are easilly cracked, with
pretty devasting results; that DNSSEC does not actually work to solve
any of its original problems.  DNSSEC suicide (Bernstein's term for
expired signatures) has already occured a couple of times.  Its all
here:

http://www.ntia.doc.gov/dns/comments/comment027.pdf

There is some more, though. Need a page on the full story of the
Vixie/Kaminksy hoax, for example.


		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 256 5494