Re: A DNS security issue that might actually have impact eventually

Randy Bush <randy@psg.com> Sun, 12 January 2014 21:43 UTC

Return-Path: <randy@psg.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 54CB11A1DFA for <ietf@ietfa.amsl.com>; Sun, 12 Jan 2014 13:43:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.539
X-Spam-Level:
X-Spam-Status: No, score=-0.539 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, RP_MATCHES_RCVD=-0.538] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KjEXba1F_Pvd for <ietf@ietfa.amsl.com>; Sun, 12 Jan 2014 13:43:03 -0800 (PST)
Received: from ran.psg.com (ran.psg.com [IPv6:2001:418:8006::18]) by ietfa.amsl.com (Postfix) with ESMTP id BB63D1A1521 for <ietf@ietf.org>; Sun, 12 Jan 2014 13:43:03 -0800 (PST)
Received: from localhost ([127.0.0.1] helo=ryuu.psg.com.psg.com) by ran.psg.com with esmtp (Exim 4.76) (envelope-from <randy@psg.com>) id 1W2Snz-0004nd-3U; Sun, 12 Jan 2014 21:42:51 +0000
Date: Mon, 13 Jan 2014 06:42:49 +0900
Message-ID: <m261povpuu.wl%randy@psg.com>
From: Randy Bush <randy@psg.com>
To: Phillip Hallam-Baker <hallam@gmail.com>
Subject: Re: A DNS security issue that might actually have impact eventually
In-Reply-To: <CAMm+Lwimtgj9NZ55mcr=KWw+24gk8SDuAiMxpUfd71J2jA+mPA@mail.gmail.com>
References: <CAMm+Lwimtgj9NZ55mcr=KWw+24gk8SDuAiMxpUfd71J2jA+mPA@mail.gmail.com>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/22.3 Mule/5.0 (SAKAKI)
MIME-Version: 1.0 (generated by SEMI 1.14.7 - "Harue")
Content-Type: multipart/signed; boundary="pgp-sign-Multipart_Mon_Jan_13_06:42:45_2014-1"; micalg="pgp-sha512"; protocol="application/pgp-signature"
Content-Transfer-Encoding: 7bit
Cc: IETF Discussion Mailing List <ietf@ietf.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 12 Jan 2014 21:43:05 -0000

the internet was a disruptive technology, and has been used for good,
bad, and indifferent.  thanks to societal forces, ongoing development of
disrupptive tools is at the edge, not the core.  bitcoin, namecoin, ...
are new disruptive technologies routing around the ossification,
cooption, and greed of the internet by LEO, NSA, ICANN, MPAA, ....
these new tools will be used for good, bad, and indifferent.

the tools which worry me are the ones where the use is only bad, e.g.
the spymall catalog.

> But if the principle of due process comes under further attack, we are
> going to find ourselves in a different domain and the demand for a
> naming infrastructure that is not exposed to the risk of arbitrary
> search and seizure will grow.

yup.  i think of it as the internet body's white blood cells trying to
heal us from disease.

randy