Re: [dns-operations] BlackHat Presentation on DNSSEC Downgrade attack

2022-08-22 Thread Keith Mitchell
Now seems like a good time to remind everyone of the OARC Conduct Policy: https://www.dns-oarc.net/oarc/policies/conduct which applies to all interactions on OARC fora, online and in-person, and including this mailing list. By all means respectfully debate the subject matter, please a

Re: [dns-operations] BlackHat Presentation on DNSSEC Downgrade attack

2022-08-22 Thread Viktor Dukhovni
On Mon, Aug 22, 2022 at 04:18:36PM +0200, Haya Shulman wrote: > [ Further ad-hominem off-topic to this list removed ] Please refrain from further efforts in that direction. > in our project we evaluated two ways to downgrade DNSSEC, by disabling > validation and by downgrading to a weaker crypto

[dns-operations] BlackHat Presentation on DNSSEC Downgrade attack

2022-08-22 Thread Haya Shulman
We allowed Peter Thomassen and Nils Wisiol to join our research. We are also not aware of any contributions they made. We removed both colleagues from our research. In fact, to Peter Thomassen we sent an email in November 2021 on behalf of all the senior researchers on this project, suggesting to h