Re: OpenDNS today announced it has adopted DNSCurve to secure DNS

Andrew Sullivan <ajs@shinkuro.com> Wed, 24 February 2010 22:39 UTC

Return-Path: <ajs@shinkuro.com>
X-Original-To: ietf@core3.amsl.com
Delivered-To: ietf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 1309A28C0DE for <ietf@core3.amsl.com>; Wed, 24 Feb 2010 14:39:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.035
X-Spam-Level:
X-Spam-Status: No, score=-2.035 tagged_above=-999 required=5 tests=[AWL=0.564, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RVk2TGZa7wGC for <ietf@core3.amsl.com>; Wed, 24 Feb 2010 14:39:33 -0800 (PST)
Received: from mail.yitter.info (mail.yitter.info [208.86.224.201]) by core3.amsl.com (Postfix) with ESMTP id 51F2128C16B for <ietf@ietf.org>; Wed, 24 Feb 2010 14:39:33 -0800 (PST)
Received: from crankycanuck.ca (69-196-144-230.dsl.teksavvy.com [69.196.144.230]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mail.yitter.info (Postfix) with ESMTPSA id D347E1ECB4E8 for <ietf@ietf.org>; Wed, 24 Feb 2010 22:41:40 +0000 (UTC)
Date: Wed, 24 Feb 2010 17:41:38 -0500
From: Andrew Sullivan <ajs@shinkuro.com>
To: ietf@ietf.org
Subject: Re: OpenDNS today announced it has adopted DNSCurve to secure DNS
Message-ID: <20100224224138.GB43510@shinkuro.com>
References: <874c02a21002231826y613b9f97ya83740ba240f7bf9@mail.gmail.com> <ABE739C5ADAC9A41ACCC72DF366B719D02C29D87@GLKMS2100.GREENLNK.NET> <a123a5d61002240700i4a68367tf901b91265f79da1@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <a123a5d61002240700i4a68367tf901b91265f79da1@mail.gmail.com>
User-Agent: Mutt/1.5.18 (2008-05-17)
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Feb 2010 22:39:34 -0000

On Wed, Feb 24, 2010 at 10:00:34AM -0500, Phillip Hallam-Baker wrote:
> I took a look at DNSCurve. Some points:
> 
> * It could certainly win.

If, just one time, the people involved in these conversations would
say what "win" means in this context, I would be a much happier
person.  (Those who know me will observe that that's not saying much.)
It is by no means plain to me that DNSCurve and DNSSEC solve the same
problems.  It's hard to say how one can win over the other in that
case.

> * It is designed as a hack rather than an extension.

This sounds to me like an argument over taste, and I don't think that
it's useful to debate it.

> * It considers real world requirements that DNSSEC does not.

And it fails to address real world requirements that DNSSEC did.  So
what?  DNSSEC doesn't solve everything that TLS does, either.  This is
the _Internet_.  Having different solutions to different problems is a
good thing, not a reason to have a Protestants vs. Catholics fight.

A

-- 
Andrew Sullivan
ajs@shinkuro.com
Shinkuro, Inc.