Re: FYI: Dan's talk on 27c3 in Berlin

Markus Stumpf <[email protected]> Mon, 14 Feb 2011 16:26:37 +0100
Newsgroups gmane.mail.qmail.general,gmane.network.djbdns
Organization maexotic.de, Muenchen, Germany
Message-ID <[email protected]>
On Mon, Feb 14, 2011 at 12:17:55AM +0000, Kevin Chadwick wrote:
> Forwarded it to unbound and got this in response.
[ ... ]
> > That was not a talk. That was a rant devoid of facts and filled with
> > unsubstantiated and by now disproven claims. Both me and Kaminsky
> > already spend too much time debunking his shit. Let's not reitterate
> > that nonsense here.
> 
> > http://dankaminsky.com/2011/01/05/djb-ccc/

*> But these are not limitations to DNSSEC as a protocol.
*> They’re implementation artifacts, no more inherent to DNSSEC
*> than publicfile‘s inability to support PHP.  (Web servers
*> were not originally designed to support dynamic content, the occasional
*> cgi-bin notwithstanding.  So, we wrote better web servers!

*LMAO* Sorry, but totally *LMAO*
Please note that he didn't write "more secure" but "better".

While IMHO some of the arguments of both sides are "valid" nobody should
think that "securing" DNS is the next best thing to sliced bread.
There will be tons of servers hacked or admins tricked to give away
passwords [1] which will (in the case of large hosters or large sites (think
twitter [2])) still have the same effect as it has now.
And it will not secure https/ssl/x.509 as this is f'up by design.

[1] HBGary Federal Hacked by Anonymous
    http://krebsonsecurity.com/2011/02/hbgary-federal-hacked-by-anonymous/
[2] DNS attack hijacks Twitter
    http://www.theregister.co.uk/2009/12/18/dns_twitter_hijack/

	\Maex