Re: How do we get the whole world to upgrade to DNSSEC capable resolvers?

Mark Andrews <Mark_Andrews@isc.org> Tue, 12 August 2008 01:09 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 651433A6E02; Mon, 11 Aug 2008 18:09:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.303
X-Spam-Level:
X-Spam-Status: No, score=-2.303 tagged_above=-999 required=5 tests=[AWL=-0.004, BAYES_00=-2.599, MIME_8BIT_HEADER=0.3]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id omUGfvqZHuyY; Mon, 11 Aug 2008 18:09:27 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 825723A69F5; Mon, 11 Aug 2008 18:09:27 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KSiJd-000797-EL for namedroppers-data@psg.com; Tue, 12 Aug 2008 01:04:49 +0000
Received: from [2001:470:1f00:820:214:22ff:fed9:fbdc] (helo=drugs.dv.isc.org) by psg.com with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69 (FreeBSD)) (envelope-from <marka@isc.org>) id 1KSiJZ-00078Q-N5 for namedroppers@ops.ietf.org; Tue, 12 Aug 2008 01:04:47 +0000
Received: from drugs.dv.isc.org (localhost [127.0.0.1]) by drugs.dv.isc.org (8.14.2/8.14.2) with ESMTP id m7C14dY3065091; Tue, 12 Aug 2008 11:04:40 +1000 (EST) (envelope-from marka@drugs.dv.isc.org)
Message-Id: <200808120104.m7C14dY3065091@drugs.dv.isc.org>
To: "Jesper G. Høy" <jesper@jhsoft.com>
Cc: 'Namedroppers WG' <namedroppers@ops.ietf.org>
From: Mark Andrews <Mark_Andrews@isc.org>
Subject: Re: How do we get the whole world to upgrade to DNSSEC capable resolvers?
In-reply-to: Your message of "Mon, 11 Aug 2008 23:47:44 +0200." <028c01c8fbfb$e44131a0$acc394e0$@com>
Date: Tue, 12 Aug 2008 11:04:39 +1000
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

> But DNSSEC was not invented to fix the Kaminsky bug (the topic of this
> thread).
> In fact DNSSEC was invented more than 10 years earlier.

	Incorrect.  It was invented to protect against several
	classes of attack of which Kaminsky is just one example.

	It was assumed back when DNSSEC was originally being developed
	that someone would work out a good method for injecting
	spoofed responses.  DNSSEC was designed to deal with that
	threat.  We just hoped we would have more deployment before
	the threat became a reality.

	Mark

-- 
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742                 INTERNET: Mark_Andrews@isc.org

--
to unsubscribe send a message to namedroppers-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://ops.ietf.org/lists/namedroppers/>