Re: [DNSOP] Pointless FUD and confusion about DNSSEC deployment

Paul Hoffman <paul.hoffman@vpnc.org> Mon, 18 August 2008 16:05 UTC

Return-Path: <dnsop-bounces@ietf.org>
X-Original-To: dnsop-archive@optimus.ietf.org
Delivered-To: ietfarch-dnsop-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id EFF8828C1B0; Mon, 18 Aug 2008 09:05:36 -0700 (PDT)
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id CC35928C1B0 for <dnsop@core3.amsl.com>; Mon, 18 Aug 2008 09:05:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.621
X-Spam-Level:
X-Spam-Status: No, score=-2.621 tagged_above=-999 required=5 tests=[AWL=-0.022, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9K5eKwyBDXdW for <dnsop@core3.amsl.com>; Mon, 18 Aug 2008 09:05:35 -0700 (PDT)
Received: from balder-227.proper.com (properopus-pt.tunnel.tserv3.fmt2.ipv6.he.net [IPv6:2001:470:1f04:392::2]) by core3.amsl.com (Postfix) with ESMTP id B6ECD28C191 for <dnsop@ietf.org>; Mon, 18 Aug 2008 09:05:34 -0700 (PDT)
Received: from [10.20.30.162] (dsl-63-249-108-169.cruzio.com [63.249.108.169]) (authenticated bits=0) by balder-227.proper.com (8.14.2/8.14.2) with ESMTP id m7IG5DX4070293 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <dnsop@ietf.org>; Mon, 18 Aug 2008 09:05:14 -0700 (MST) (envelope-from paul.hoffman@vpnc.org)
Mime-Version: 1.0
Message-Id: <p06240816c4cf4c49aba6@[10.20.30.162]>
In-Reply-To: <8D67AF7D-FAED-4084-AF52-E144C9EF2BE5@rfc1035.com>
References: <Pine.LNX.4.44.0808172349500.1117-100000@citation2.av8.net> <8D67AF7D-FAED-4084-AF52-E144C9EF2BE5@rfc1035.com>
Date: Mon, 18 Aug 2008 09:02:20 -0700
To: dnsop@ietf.org
From: Paul Hoffman <paul.hoffman@vpnc.org>
Subject: Re: [DNSOP] Pointless FUD and confusion about DNSSEC deployment
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/pipermail/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Sender: dnsop-bounces@ietf.org
Errors-To: dnsop-bounces@ietf.org

At 1:27 PM +0100 8/18/08, Jim Reid wrote:
>The fact is DNSSEC is the *only* game in town for preventing cache poisoning.

Note the subject of this particular thread. A more carefully-worded 
sentence would be "The fact is DNSSEC is the *only* game in town for 
completely preventing cache poisoning." We have methods to reduce an 
attacker's ability to poison caches effectively.

--Paul Hoffman, Director
--VPN Consortium
_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop