Re: [DNSOP] Whiskey Tango Foxtrot on key lengths...

Paul Wouters <paul@nohats.ca> Wed, 02 April 2014 03:06 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: dnsop@ietfa.amsl.com
Delivered-To: dnsop@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 07CEE1A00D4 for <dnsop@ietfa.amsl.com>; Tue, 1 Apr 2014 20:06:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.01
X-Spam-Level:
X-Spam-Status: No, score=-2.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id juD_Er3-B726 for <dnsop@ietfa.amsl.com>; Tue, 1 Apr 2014 20:06:44 -0700 (PDT)
Received: from bofh.nohats.ca (bofh.nohats.ca [76.10.157.69]) by ietfa.amsl.com (Postfix) with ESMTP id CE5D81A00D5 for <dnsop@ietf.org>; Tue, 1 Apr 2014 20:06:43 -0700 (PDT)
Received: from bofh.nohats.ca (bofh.nohats.ca [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id 226EF813B5; Tue, 1 Apr 2014 23:06:38 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1396407998; bh=KvqvDYitoL2DBFfWV14G9VbhPrk2dlFRBX+1szQbPfU=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=QZ0s6iUK4ibiOeG3aFGKEFBoA/YTZZ8unqOZlFgB2kyHRd/75FgEqS2hqKhdboTTO ZitCp5kVggVf+ZNrHsQT6MiaatdUCoZQcTotd7TlOLLUADlsbGwbtVVgWmQRJIWVVa OVTeopjmYZrYnqjGoVh5PMYRsCCVNWLSW6hZufhY=
Received: from localhost (paul@localhost) by bofh.nohats.ca (8.14.7/8.14.7/Submit) with ESMTP id s3236baH021924; Tue, 1 Apr 2014 23:06:37 -0400
X-Authentication-Warning: bofh.nohats.ca: paul owned process doing -bs
Date: Tue, 1 Apr 2014 23:06:37 -0400 (EDT)
From: Paul Wouters <paul@nohats.ca>
To: Olafur Gudmundsson <ogud@ogud.com>
In-Reply-To: <CFA0ED6F-6800-4638-90B0-CD414301C501@ogud.com>
Message-ID: <alpine.LFD.2.10.1404012257180.7948@bofh.nohats.ca>
References: <0EA28BE8-E872-46BA-85FD-7333A1E13172@icsi.berkeley.edu> <53345C77.8040603@uni-due.de> <B7893984-2FAD-472D-9A4E-766A5C212132@pch.net> <102C13BE-E45E-437A-A592-FA373FF5C8F0@ogud.com> <474B0834-C16B-4843-AA0A-FC2A2085FEFB@icsi.berkeley.edu> <CFA0ED6F-6800-4638-90B0-CD414301C501@ogud.com>
User-Agent: Alpine 2.10 (LFD 1266 2009-07-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Archived-At: http://mailarchive.ietf.org/arch/msg/dnsop/YYwDCKljBGotSJWibXkHuDYFYk0
Cc: dnsop <dnsop@ietf.org>
Subject: Re: [DNSOP] Whiskey Tango Foxtrot on key lengths...
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop/>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 02 Apr 2014 03:06:49 -0000

On Tue, 1 Apr 2014, Olafur Gudmundsson wrote:

> Over the years I have been saying use keys that are appropriate, thus for someone like Paypal it makes sense to have strong keys,
> but for my private domain does it matter what key size I use?

That depends. How much money is in your ogud@ogud.com paypal account?

Seriously though, security strength should not depend on who uses
it. Just like opensource software does not tell you for what you can
use the software. No one can make consistent judgement calls on that.

We already see security that is only available to "important
players", like EV certificates, and browser vendors pinning their own
certificates, OS vendors hardcoding their IP addresses. It's a position
of priviledge. We should not design or deploy to accomodate that. One
the of advantages of DNSSEC is that we can give everyone the highest
levels of security. Don't make a security economy class.

People running giant DNS resolver farms can add a few boxes to their
farm. People running resolvers on the stub can take the extra hit for
the few domains they are resolving.

Paul