Re: The problem I see with DNSSEC as a potential end user and administrator.

" Ondřej Surý " <ondrej.sury@nic.cz> Fri, 08 August 2008 12:07 UTC

Return-Path: <owner-namedroppers@ops.ietf.org>
X-Original-To: ietfarch-dnsext-archive@core3.amsl.com
Delivered-To: ietfarch-dnsext-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id BE1FD3A6CBB; Fri, 8 Aug 2008 05:07:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 3.707
X-Spam-Level: ***
X-Spam-Status: No, score=3.707 tagged_above=-999 required=5 tests=[AWL=0.821, BAYES_20=-0.74, FH_RELAY_NODNS=1.451, FM_FORGED_GMAIL=0.622, HELO_MISMATCH_COM=0.553, J_CHICKENPOX_23=0.6, MIME_8BIT_HEADER=0.3, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id i69XIqFIwaaV; Fri, 8 Aug 2008 05:07:01 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 899293A67B2; Fri, 8 Aug 2008 05:07:01 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-namedroppers@ops.ietf.org>) id 1KRQeu-0006J4-06 for namedroppers-data@psg.com; Fri, 08 Aug 2008 12:01:28 +0000
Received: from [64.233.182.184] (helo=nf-out-0910.google.com) by psg.com with esmtp (Exim 4.69 (FreeBSD)) (envelope-from <ondrej.sury@nic.cz>) id 1KRQep-0006IC-5a for namedroppers@ops.ietf.org; Fri, 08 Aug 2008 12:01:25 +0000
Received: by nf-out-0910.google.com with SMTP id g13so845299nfb.11 for <namedroppers@ops.ietf.org>; Fri, 08 Aug 2008 05:01:20 -0700 (PDT)
Received: by 10.210.71.12 with SMTP id t12mr5411317eba.36.1218196880099; Fri, 08 Aug 2008 05:01:20 -0700 (PDT)
Received: by 10.210.121.1 with HTTP; Fri, 8 Aug 2008 05:01:20 -0700 (PDT)
Message-ID: <e90946380808080501p2859b4b8ma406d848f0a08d3@mail.gmail.com>
Date: Fri, 08 Aug 2008 14:01:20 +0200
From: Ondřej Surý <ondrej.sury@nic.cz>
To: Namedroppers <namedroppers@ops.ietf.org>
Subject: Re: The problem I see with DNSSEC as a potential end user and administrator.
In-Reply-To: <20080808102132.GO18233@zaphods.net>
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: base64
Content-Disposition: inline
References: <489BE047.1010100@e164.org> <e90946380808080203g65c99a72meca9db15c1194df1@mail.gmail.com> <489C0E08.3040406@e164.org> <e90946380808080218n7acddd46gd99d39fa71edcb26@mail.gmail.com> <489C112A.8000306@e164.org> <e90946380808080232w756e1123u2237fa1ac846173f@mail.gmail.com> <489C140C.60205@e164.org> <e90946380808080252r35e88807v15e904d10c73cb76@mail.gmail.com> <20080808102132.GO18233@zaphods.net>
Sender: owner-namedroppers@ops.ietf.org
Precedence: bulk
List-ID: <namedroppers.ops.ietf.org>

2008/8/8 Stefan Schmidt <zaphodb@zaphods.net>:
> On Fri, Aug 08, 2008 at 11:52:08AM +0200, Ond??ej Surý wrote:
>> > What was, is meaningless to those that don't know or care, what is, is
>> > all that matters if you are trying to sell DNSSEC to the unwashed masses
>> > that aren't drinking the koolaid.
>>
>> Well, we don't need to sell it to masses.  We just need to educated registrars,
>> ISPs and big zone hosters, where people with (at least some) clue works.
>> And that's something what we are working on.
>
> If you don't deploy it to a hundred percent it simply won't be 'the solution'
> to the spoofing and man-in-the-middle problem as some people here like to
> think. Saturation is important to the success of a protocol, think of blueray
> vs. hd-dvd so you need not only to address the forbes500 but also
> www.mylittlewebsitethatsellsstuff.cctld, that kind of thing is often run by
> small companys that lack the clue you want people to have.

That's the reason why to talk to registrars, webhosters and zone hosters (which
is almost the same people here).  That way you hit not only top companies
but also lots and lots of small folks.

Ondrej
-- 
 Ondřej Surý
 technický ředitel/Chief Technical Officer
 -----------------------------------------
 CZ.NIC, z.s.p.o. -- .cz domain registry
 Americká 23,120 00 Praha 2,Czech Republic
 mailto:ondrej.sury@nic.cz http://nic.cz/
 sip:ondrej.sury@nic.cz tel:+420.222745110
 mob:+420.739013699 fax:+420.222745112
 -----------------------------------------
¶‹§²æìr¸›zǧu©ž²Æ zÚ'jg®Šiz»+z«ž²Ú)²'­~ŠàÂ+a¶°¢·nžË›±Êâmè§jȧ‚W¥Šwš²Ø^™ë,j­{[¡Üš­Èb½èm¶Ÿÿ¢›"z×è®åŠËlþv¦yÚ覗«³