Re: [saag] What does DNSSec protect? (Re: Last Call: <draft-dukhovni-opportunistic-security-01.txt> (Opportunistic Security: some protection most of the time) to Informational RFC)
Andrew Sullivan <ajs@anvilwalrusden.com> Sun, 10 August 2014 22:37 UTC
Return-Path: <ajs@anvilwalrusden.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7B2991A010E for <ietf@ietfa.amsl.com>; Sun, 10 Aug 2014 15:37:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.141
X-Spam-Level:
X-Spam-Status: No, score=-0.141 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_MISMATCH_INFO=1.448, HOST_MISMATCH_NET=0.311] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id elQgmU5QcVt0 for <ietf@ietfa.amsl.com>; Sun, 10 Aug 2014 15:37:30 -0700 (PDT)
Received: from mx1.yitter.info (ow5p.x.rootbsd.net [208.79.81.114]) (using TLSv1 with cipher ADH-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 68B661A00F5 for <ietf@ietf.org>; Sun, 10 Aug 2014 15:37:30 -0700 (PDT)
Received: from mx1.yitter.info (c-76-118-173-172.hsd1.nh.comcast.net [76.118.173.172]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.yitter.info (Postfix) with ESMTPSA id 728D68A031 for <ietf@ietf.org>; Sun, 10 Aug 2014 22:37:28 +0000 (UTC)
Date: Sun, 10 Aug 2014 18:37:26 -0400
From: Andrew Sullivan <ajs@anvilwalrusden.com>
To: ietf@ietf.org
Subject: Re: [saag] What does DNSSec protect? (Re: Last Call: <draft-dukhovni-opportunistic-security-01.txt> (Opportunistic Security: some protection most of the time) to Informational RFC)
Message-ID: <20140810223726.GC40040@mx1.yitter.info>
References: <5B9A4046A1CB9ECDF6B77ACC@JcK-HP8200.jck.com> <20140810173503.86832.qmail@joyce.lan> <20140810181807.GA84281@mx1.yitter.info> <17F130BD6920FB05E6A82823@JcK-HP8200.jck.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <17F130BD6920FB05E6A82823@JcK-HP8200.jck.com>
User-Agent: Mutt/1.5.21 (2010-09-15)
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/uuLuXzLfzJ2OPFADLcVOD72SIJ8
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 10 Aug 2014 22:37:31 -0000
On Sun, Aug 10, 2014 at 03:37:10PM -0400, John C Klensin wrote: > statements we make about it when we are being careful. It is > about people engaging in hyperbole of the nature of "you have > DNSSEC, now you are safe" (with the implication of "from all > sorts of attacks") or using other language that implies that the > threats that you (and John L.) have identified. Yes, I'm sorry. I was over-reacting to something John L. said, because I've recently been subject to a long harangue about how DNSSEC doesn't protect anything at all. My apologies to all. Best regards, A -- Andrew Sullivan ajs@anvilwalrusden.com
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Joe Touch
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Dave Crocker
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Stephen Farrell
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Joe Touch
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Joe Touch
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Michael Richardson
- Re: Last Call: <draft-dukhovni-opportunistic-secu… S Moonesamy
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Randy Bush
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Viktor Dukhovni
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Eliot Lear
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Stephen Farrell
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Murray S. Kucherawy
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Eliot Lear
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Stephen Farrell
- SMTP authentication (not soon) Viktor Dukhovni
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Sam Hartman
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Nico Williams
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Nico Williams
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Nico Williams
- Re: SMTP authentication (not soon) Niels Dettenbach
- Re: SMTP authentication (not soon) Phillip Hallam-Baker
- Re: SMTP authentication (not soon) Viktor Dukhovni
- Re: SMTP authentication (not soon) Stephen Farrell
- Re: SMTP authentication (not soon) ned+ietf
- Re: SMTP authentication (not soon) Dave Cridland
- Re: SMTP authentication (not soon) Viktor Dukhovni
- Re: SMTP authentication (not soon) Dave Cridland
- Re: SMTP authentication (not soon) Eliot Lear
- Re: SMTP authentication (not soon) Phillip Hallam-Baker
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Viktor Dukhovni
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Rene Struik
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Rene Struik
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Rene Struik
- Re: SMTP authentication (not soon) Dan Wing
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Dave Crocker
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Sam Hartman
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Tim Bray
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Joe Touch
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Stephen Kent
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Kent
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… t.p.
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Martin Thomson
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Henry B Hotz
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Kent
- Re: [saag] Last Call: <draft-dukhovni-opportunist… t.p.
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Martin Rex
- Re: Last Call: (pushed -02 update) <draft-dukhovn… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Kent
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Kent
- Target audience? (was Re: [saag] Last Call: <draf… Dave Crocker
- Re: Target audience? (was Re: [saag] Last Call: <… Viktor Dukhovni
- Re: Target audience? (was Re: [saag] Last Call: <… Viktor Dukhovni
- Re: Target audience? (was Re: [saag] Last Call: <… Scott Kitterman
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Kent
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Dave Crocker
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Dave Crocker
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Dave Crocker
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Scott Kitterman
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Dave Crocker
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Scott Kitterman
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Patrik Fältström
- Wikipedia, was Target audience? (was Last Call Op… Alessandro Vesely
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Farrell
- Best Effort Key Management (was Re: [saag] Last C… Dave Crocker
- Re: Best Effort Key Management (was Re: [saag] La… Stephen Farrell
- Re: Best Effort Key Management (was Re: [saag] La… Stephen Farrell
- Re: Best Effort Key Management (was Re: [saag] La… Dave Crocker
- Re: Best Effort Key Management (was Re: [saag] La… Viktor Dukhovni
- Re: Best Effort Key Management (was Re: [saag] La… Dave Crocker
- Re: Best Effort Key Management (was Re: [saag] La… Stephen Farrell
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Kent
- Re: [saag] Best Effort Key Management (was Re: La… Viktor Dukhovni
- Re: Best Effort Key Management (was Re: [saag] La… Paul Wouters
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Nico Williams
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Viktor Dukhovni
- Re: Best Effort Key Management (was Re: [saag] La… Scott Kitterman
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Stephen Farrell
- Individual submission (was: Best Effort Key Manag… S Moonesamy
- Re: Individual submission Dave Crocker
- Re: [saag] Last Call: <draft-dukhovni-opportunist… John C Klensin
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Mark Andrews
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: Individual submission Abdussalam Baryun
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Nico Williams
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Nico Williams
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Paul Wouters
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Paul Wouters
- Re: [saag] Fwd: Last Call: <draft-dukhovni-opport… Rene Struik
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Nico Williams
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Nico Williams
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Nico Williams
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Stephen Farrell
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Stephen Farrell
- Re: Target audience? (was Re: [saag] Last Call: <… Stephen Farrell
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Paul Wouters
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Nico Williams
- What does DNSSec protect? (Re: [saag] Last Call: … Dave Crocker
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Steve Crocker
- Re: What does DNSSec protect? (Re: [saag] Last Ca… Paul Wouters
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Donald Eastlake
- Re: [saag] What does DNSSec protect? (Re: Last Ca… John C Klensin
- Re: [saag] What does DNSSec protect? (Re: Last Ca… John Levine
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Andrew Sullivan
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Brian E Carpenter
- Re: [saag] What does DNSSec protect? (Re: Last Ca… John C Klensin
- Re: [saag] What does DNSSec protect? (Re: Last Ca… John C Klensin
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Henry B Hotz
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Andrew Sullivan
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Mark Andrews
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Nico Williams
- Re: [saag] What does DNSSec protect? (Re: Last Ca… Nico Williams
- Re: [saag] What does DNSSec protect? (Re: Last Ca… João Damas
- Re: [saag] What does DNSSec protect? (Re: Last Ca… manning
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Stephen Farrell
- Re: Last Call: <draft-dukhovni-opportunistic-secu… Stephen Kent
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Viktor Dukhovni
- Protocol Design Pattern (was Re: [saag] Last Call… Dave Crocker
- Re: Protocol Design Pattern (was Re: [saag] Last … Scott Kitterman
- Re: Protocol Design Pattern (was Re: [saag] Last … Dave Crocker
- Re: [saag] Protocol Design Pattern (was Re: Last … Benjamin Kaduk
- Re: Protocol Design Pattern (was Re: [saag] Last … Nico Williams
- Re: Protocol Design Pattern (was Re: [saag] Last … Paul Wouters
- Re: Protocol Design Pattern (was Re: [saag] Last … Nico Williams
- Re: Protocol Design Pattern (was Re: [saag] Last … Dave Crocker
- Re: Protocol Design Pattern (was Re: [saag] Last … Nico Williams
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Stephen Kent
- Re: Protocol Design Pattern (was Re: [saag] Last … Stephen Kent
- Re: Protocol Design Pattern (was Re: [saag] Last … Stephen Farrell
- Re: Protocol Design Pattern (was Re: [saag] Last … Stephen Farrell
- Re: [saag] Last Call: <draft-dukhovni-opportunist… Benjamin Kaduk
- Re: [saag] Protocol Design Pattern (was Re: Last … Benjamin Kaduk
- Re: [saag] Protocol Design Pattern (was Re: Last … Benjamin Kaduk
- Re: [saag] Protocol Design Pattern (was Re: Last … Dave Crocker
- Re: Protocol Design Pattern (was Re: [saag] Last … Eliot Lear
- Re: [saag] Protocol Design Pattern (was Re: Last … Stephen Kent
- Re: [saag] Protocol Design Pattern (was Re: Last … Stephen Farrell
- Re: [saag] Protocol Design Pattern (was Re: Last … Benjamin Kaduk
- Re: [saag] Protocol Design Pattern (was Re: Last … Dave Crocker
- Re: [saag] Protocol Design Pattern (was Re: Last … Stephen Kent
- Re: [saag] Protocol Design Pattern (was Re: Last … Stephen Kent
- Re: [saag] Protocol Design Pattern (was Re: Last … Benjamin Kaduk
- Re: Protocol Design Pattern (was Re: [saag] Last … t.p.
- Re: [saag] Protocol Design Pattern (was Re: Last … Eliot Lear
- Re: [saag] Protocol Design Pattern (was Re: Last … Benjamin Kaduk
- Re: [saag] Protocol Design Pattern (was Re: Last … Henry B (Hank) Hotz, CISSP