Re: DS and Opt-in - a proposal

"Steven M. Bellovin" <smb@research.att.com> Fri, 04 January 2002 06:19 UTC

Received: from psg.com (exim@psg.com [147.28.0.62]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA20175 for <dnsext-archive@lists.ietf.org>; Fri, 4 Jan 2002 01:19:12 -0500 (EST)
Received: from lserv by psg.com with local (Exim 3.33 #1) id 16MNT1-0008lN-00 for namedroppers-data@psg.com; Thu, 03 Jan 2002 22:04:35 -0800
Received: from rip.psg.com ([147.28.0.39]) by psg.com with esmtp (Exim 3.33 #1) id 16MNT1-0008lH-00 for namedroppers@ops.ietf.org; Thu, 03 Jan 2002 22:04:35 -0800
Received: from randy by rip.psg.com with local (Exim 3.33 #1) id 16MNT1-000M4u-00 for namedroppers@ops.ietf.org; Thu, 03 Jan 2002 22:04:35 -0800
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Message-Id: <20020104040226.0E1AB7B7D@berkshire.research.att.com>
From: "Steven M. Bellovin" <smb@research.att.com>
To: Roy Arends <Roy.Arends@nominum.com>
Cc: "Olaf M. Kolkman" <olaf@ripe.net>, namedroppers@ops.ietf.org
Subject: Re: DS and Opt-in - a proposal
Date: Thu, 03 Jan 2002 23:02:26 -0500
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk

In message <20011228111431.V13525-100000@node10c4d.a2000.nl>, Roy Arends writes
:

>We are not talking about authenticated [denial of] existence in general,
>only about authenticated [denial of] existence of unsecured names.
>
>Imagine going into a tourist office (.city), the only authoritative
>place in town to get the authenticatable, verifiable information from.

Let me point folks at draft-bellovin-dnsext-bloomfilt-00.txt, which is 
designed to address that issue.

(a) Is the issue important enough to be worth introducing a brand-new 
mechanism at this time?

(b) Is the false positive rate acceptable?

(c) If so, is the protocol complexity of this suggestion acceptable?

(d) Is it operationally real?

		--Steve Bellovin, http://www.research.att.com/~smb
		Full text of "Firewalls" book now at http://www.wilyhacker.com




to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.