Re: [Trans] On the worthiness of DNSSEC and PKI (Re: DNSSEC also needs CT)

Nico Williams <nico@cryptonector.com> Fri, 09 May 2014 23:51 UTC

Return-Path: <nico@cryptonector.com>
X-Original-To: trans@ietfa.amsl.com
Delivered-To: trans@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 063421A011E for <trans@ietfa.amsl.com>; Fri, 9 May 2014 16:51:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.044
X-Spam-Level:
X-Spam-Status: No, score=-1.044 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, IP_NOT_FRIENDLY=0.334] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VH6FMQNpPbVz for <trans@ietfa.amsl.com>; Fri, 9 May 2014 16:50:59 -0700 (PDT)
Received: from homiemail-a89.g.dreamhost.com (sub4.mail.dreamhost.com [69.163.253.135]) by ietfa.amsl.com (Postfix) with ESMTP id E49E21A011B for <trans@ietf.org>; Fri, 9 May 2014 16:50:59 -0700 (PDT)
Received: from homiemail-a89.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a89.g.dreamhost.com (Postfix) with ESMTP id 0A89931805D for <trans@ietf.org>; Fri, 9 May 2014 16:50:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h= mime-version:date:message-id:subject:from:to:cc:content-type; s= cryptonector.com; bh=uY3dXLBgBvuiNFlsaafKEEChstw=; b=ZdxJj1SKFdG c++Iu4bgAh2Rlp7meeMM0rUcPzRkhHYKtli2DDT6hFKxt7to5evwvMLbroEDFTfj MK2x66V+OrIyVwTYegd8VfE+rDbHGxQk+DywPozjvImTCsCxzyXKJFChGXJB1ooT pUYpp0si8VNPg1n5yb4C2lY4jr+kjH2I=
Received: from mail-wi0-f174.google.com (mail-wi0-f174.google.com [209.85.212.174]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a89.g.dreamhost.com (Postfix) with ESMTPSA id AE267318059 for <trans@ietf.org>; Fri, 9 May 2014 16:50:54 -0700 (PDT)
Received: by mail-wi0-f174.google.com with SMTP id r20so2069920wiv.13 for <trans@ietf.org>; Fri, 09 May 2014 16:50:53 -0700 (PDT)
MIME-Version: 1.0
X-Received: by 10.180.108.147 with SMTP id hk19mr5338056wib.42.1399679453372; Fri, 09 May 2014 16:50:53 -0700 (PDT)
Received: by 10.216.29.200 with HTTP; Fri, 9 May 2014 16:50:53 -0700 (PDT)
Date: Fri, 09 May 2014 18:50:53 -0500
Message-ID: <CAK3OfOjRg3B69WBhcVxCFZBZt3LeOz_F=giqT37+FUPC+OxTwA@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Tao Effect <contact@taoeffect.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: http://mailarchive.ietf.org/arch/msg/trans/d56QpDxwmxHPRG4BdhXkM_PhE4Y
Cc: "Mehner, Carl" <Carl.Mehner@usaa.com>, "trans@ietf.org" <trans@ietf.org>
Subject: Re: [Trans] On the worthiness of DNSSEC and PKI (Re: DNSSEC also needs CT)
X-BeenThere: trans@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Public Notary Transparency working group discussion list <trans.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/trans>, <mailto:trans-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/trans/>
List-Post: <mailto:trans@ietf.org>
List-Help: <mailto:trans-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/trans>, <mailto:trans-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 May 2014 23:51:02 -0000

On Fri, May 9, 2014 at 6:27 PM, Tao Effect <contact@taoeffect.com> wrote:
> Thank you Nico for at least noting it. ;-)

That's all I'll do for now.  I don't have time to engage your position
at this time.  Surely others already have anyways.

> This list is about making CT happen, and here I come saying that CT is a

Right.

> horrible and insecure protocol.

Maybe.

> Such a civil reply is almost unexpected. ^_^

By "noted" I meant to say that yes, I took note of your position but I
don't want to discuss that topic in the context of "DNSSEC needs CT"
-- the two matters are separable.  To discuss your response in the
same thread would just create noise.  At any rate, I don't have time
to address it separately anyways.  Feel free to educate us though.

Nico
--