Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-20 Thread Paul Wouters
On Fri, 20 Mar 2015, Watson Ladd wrote: What's wrong with DNScrypt? It's just a preconfigured new VPN protocol where the clients need to know the public key of this new VPN protocol provider to setup a VPN limited to "DNS"Curve packets. - It is incompatible with IETF VPN protocols (IPsec/IKE,

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-20 Thread Phillip Hallam-Baker
On Fri, Mar 20, 2015 at 10:55 AM, Watson Ladd wrote: > On Fri, Mar 20, 2015 at 3:33 AM, Stephen Farrell > wrote: >> >> >> On 19/03/15 23:43, Zhiwei Yan wrote: >>> Hi, all, I think it's better that this draft contains some solution >>> about the client authentication to decrease/avoid the DoS atta

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-20 Thread Watson Ladd
On Fri, Mar 20, 2015 at 3:33 AM, Stephen Farrell wrote: > > > On 19/03/15 23:43, Zhiwei Yan wrote: >> Hi, all, I think it's better that this draft contains some solution >> about the client authentication to decrease/avoid the DoS attack. But >> it's really not the focus of this draft. In order to

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-20 Thread Phillip Hallam-Baker
On Fri, Mar 20, 2015 at 6:33 AM, Stephen Farrell wrote: > > > On 19/03/15 23:43, Zhiwei Yan wrote: > > Hi, all, I think it's better that this draft contains some solution > > about the client authentication to decrease/avoid the DoS attack. But > > it's really not the focus of this draft. In orde

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-20 Thread Stephen Farrell
On 19/03/15 23:43, Zhiwei Yan wrote: > Hi, all, I think it's better that this draft contains some solution > about the client authentication to decrease/avoid the DoS attack. But > it's really not the focus of this draft. In order to solve this > problem, many other schemes can be used, such as D

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-20 Thread W.C.A. Wijngaards
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi Paul, On 20/03/15 01:59, Paul Hoffman wrote: > On Mar 19, 2015, at 8:49 AM, W.C.A. Wijngaards > wrote: >> On 14/03/15 01:19, Paul Hoffman wrote: >>> Greetings again. I mentioned this to Wouters a while ago, >>> before the DPRIVE WG started, but

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-19 Thread Paul Hoffman
On Mar 19, 2015, at 7:00 PM, Watson Ladd wrote: > > On Thu, Mar 19, 2015 at 5:59 PM, Paul Hoffman wrote: >> On Mar 19, 2015, at 8:49 AM, W.C.A. Wijngaards wrote: >>> On 14/03/15 01:19, Paul Hoffman wrote: Greetings again. I mentioned this to Wouters a while ago, before the DPRIVE WG s

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-19 Thread Watson Ladd
On Thu, Mar 19, 2015 at 5:59 PM, Paul Hoffman wrote: > On Mar 19, 2015, at 8:49 AM, W.C.A. Wijngaards wrote: >> On 14/03/15 01:19, Paul Hoffman wrote: >> > Greetings again. I mentioned this to Wouters a while ago, before >> > the DPRIVE WG started, but it is worth bringing up here if the WG >> >

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-19 Thread Paul Hoffman
On Mar 19, 2015, at 8:49 AM, W.C.A. Wijngaards wrote: > On 14/03/15 01:19, Paul Hoffman wrote: > > Greetings again. I mentioned this to Wouters a while ago, before > > the DPRIVE WG started, but it is worth bringing up here if the WG > > is considering this for widespread deployment. > > > > draft

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-19 Thread Zhiwei Yan
Hi, all, I think it's better that this draft contains some solution about the client authentication to decrease/avoid the DoS attack. But it's really not the focus of this draft. In order to solve this problem, many other schemes can be used, such as DHCP, SAVI and DANE. Anyway, this draft can m

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-19 Thread Paul Wouters
On Thu, 19 Mar 2015, W.C.A. Wijngaards wrote: Could perhaps a different algorithm, like ED25519, provide better performance, and would that performance then be adequate? Different algorithms differ in performance how much? A factor 2? Maybe 10? Compared to a botnet, I don't think that it is ve

Re: [dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-19 Thread W.C.A. Wijngaards
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi Paul, On 14/03/15 01:19, Paul Hoffman wrote: > Greetings again. I mentioned this to Wouters a while ago, before > the DPRIVE WG started, but it is worth bringing up here if the WG > is considering this for widespread deployment. > > draft-wijnga

[dns-privacy] draft-wijngaards-dnsop-confidentialdns and DDoS

2015-03-13 Thread Paul Hoffman
Greetings again. I mentioned this to Wouters a while ago, before the DPRIVE WG started, but it is worth bringing up here if the WG is considering this for widespread deployment. draft-wijngaards-dnsop-confidentialdns running over UDP opens up the server to a trivial CPU denial-of-service becaus