Re: OpenDNS today announced it has adopted DNSCurve to secure DNS

Joe Baptista <baptista@publicroot.org> Thu, 25 February 2010 02:41 UTC

Return-Path: <publicroot.info@gmail.com>
X-Original-To: ietf@core3.amsl.com
Delivered-To: ietf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D49B928C2A3 for <ietf@core3.amsl.com>; Wed, 24 Feb 2010 18:41:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.614
X-Spam-Level:
X-Spam-Status: No, score=-1.614 tagged_above=-999 required=5 tests=[AWL=0.047, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, SARE_MILLIONSOF=0.315]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AplxHSQphqHz for <ietf@core3.amsl.com>; Wed, 24 Feb 2010 18:41:31 -0800 (PST)
Received: from mail-fx0-f213.google.com (mail-fx0-f213.google.com [209.85.220.213]) by core3.amsl.com (Postfix) with ESMTP id 91AE028C253 for <ietf@ietf.org>; Wed, 24 Feb 2010 18:41:31 -0800 (PST)
Received: by fxm5 with SMTP id 5so5989840fxm.29 for <ietf@ietf.org>; Wed, 24 Feb 2010 18:43:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:sender:received:in-reply-to :references:date:x-google-sender-auth:message-id:subject:from:to:cc :content-type; bh=zjQnPJz+Cj+fesSlf2GGy3enVgw0Kw4OkZiuALhUN9o=; b=BfsxzKh4yvIlYE7eR6ph7ddDI/HcRBy4Qjn01aoEBg/Zvn5sgjbVCTIS/EJKo/+1BY wxdYpX+YuZfqSXo9GDbjkU23ZT8aMDXDYHtA1AWL/BS7nKsDlLGcOH4bl36xr3SzJGGz mQg9cxFCbTsUT1ToPCfEXltj0CEmLKhTMPyGI=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; b=u9pBw/BIUQemk+QnY/IkWsJQe9MflhAHouvxO1VsikZbEuYZvVXUnwupT6k846h22c 699ulySy4b2kNPQZUmmtVTZxVu9IneYkjQvxuAsogGNBZ1c4RmuHWw1EgbrksYr/b0PE CE4r3HLScm4ehrngxNExxnijA4FrdL1FYYRKQ=
MIME-Version: 1.0
Sender: publicroot.info@gmail.com
Received: by 10.223.16.199 with SMTP id p7mr499613faa.88.1267065816786; Wed, 24 Feb 2010 18:43:36 -0800 (PST)
In-Reply-To: <p0624080ec7ab1f650ef1@10.20.30.158>
References: <874c02a21002231826y613b9f97ya83740ba240f7bf9@mail.gmail.com> <ABE739C5ADAC9A41ACCC72DF366B719D02C29D87@GLKMS2100.GREENLNK.NET> <a123a5d61002240700i4a68367tf901b91265f79da1@mail.gmail.com> <alpine.LSU.2.00.1002241754550.16971@hermes-2.csi.cam.ac.uk> <p0624080ec7ab1f650ef1@10.20.30.158>
Date: Wed, 24 Feb 2010 21:43:36 -0500
X-Google-Sender-Auth: cbbf8826797a4b31
Message-ID: <874c02a21002241843wc5cf921q242fcb7197718cf9@mail.gmail.com>
Subject: Re: OpenDNS today announced it has adopted DNSCurve to secure DNS
From: Joe Baptista <baptista@publicroot.org>
To: Paul Hoffman <paul.hoffman@vpnc.org>
Content-Type: multipart/alternative; boundary="001517448592eaa8ac048063bf27"
Cc: ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Feb 2010 02:41:33 -0000

On Wed, Feb 24, 2010 at 1:27 PM, Paul Hoffman <paul.hoffman@vpnc.org> wrote:

>
> DNSCurve also assumes that authoritative name servers are willing to do
> orders of magnitude more calculations per second, all the time, than DNSSEC
> requires of them. That is, cryptographic calculations are needed for every
> response. Placing that burden on the DNS may or may not be acceptable to
> current operators. It may or may not also lead to less stability.
>


That made me laugh. I would rather burden a server with added clicks then
the added burden DNSSEC will cause the world - not only in bandwidth - which
will explode under DNSSEC but also the economic costs to business and
individuals of migrating hundreds of millions of domains in the DNSSEC make
work project. Let's not forget DNSSEC re-engineers the Internet to a
centralized control model that defeats the end to end basics.

regards
joe baptista