Re: [DNSOP] I-D Action:draft-ietf-dnsop-reflectors-are-evil-06.txt

2008-09-01 Thread Dean Anderson
On Mon, 1 Sep 2008, David Conrad wrote: > > This draft reminds me of the claims that open relays somehow > > promoted spam. > [Trademark Dean Anderson paranoiac drivel deleted] You misuse the word paranoid. The word 'paranoid', means one has an unjustified fear. I have no 'unjustified fear', n

Re: [DNSOP] I think we may have a solution - DNSCurve

2008-09-01 Thread Dean Anderson
On Mon, 1 Sep 2008, Paul Hoffman wrote: > Or perhaps not. Dan's views of what facts are obvious for patents are > irrelevant to whether or not someone would want to challenge a > patent-holder in a costly patent fight; One can't challenge a patent's validity merely by claiming that it is 'irr

Re: [DNSOP] I-D Action:draft-ietf-dnsop-reflectors-are-evil-06.txt

2008-09-01 Thread David Conrad
Dean, On Sep 1, 2008, at 6:35 PM, Dean Anderson wrote: > Given that we now have some high-profile DNSSEC test zones (thanks to > David Conrad), ... You're quite welcome, but I really can't take the credit -- the IAB really was the instigator of the ns.iana.org service (assuming that's what yo

Re: [DNSOP] I-D Action:draft-ietf-dnsop-reflectors-are-evil-06.txt

2008-09-01 Thread Dean Anderson
Has there been any subsequent attacks since the motivating attack was reported? Given that we now have some high-profile DNSSEC test zones (thanks to David Conrad), there is now no reason at all to use a recursor in a DDOS attack. One would merely make DNSSEC queries against a high-profile auth

Re: [DNSOP] Anycast was Re: Cache poisoning on DNSSEC

2008-09-01 Thread Dean Anderson
On Mon, 1 Sep 2008, Ralf Weber wrote: > Well we tested it as good as we could in our small lab Ahh. This is where your engineers are supposed to consider theory, in this case RFC1546 and RFC1812. Did you tell your senior management that RFC1546 explicitly states that Anycast isn't suitable for

Re: [DNSOP] I think we may have a solution - DNSCurve

2008-09-01 Thread Paul Hoffman
At 11:13 PM +0200 9/1/08, bert hubert wrote: >On Mon, Sep 01, 2008 at 04:49:12PM -0400, Paul Wouters wrote: >> On Sun, 31 Aug 2008, David Conrad wrote: >> >> > 5. I suspect having encryption will make getting export licenses more >> > complicated. >> >> 6. Ellipctic Curve is patent encumbered

Re: [DNSOP] I think we may have a solution - DNSCurve

2008-09-01 Thread bert hubert
On Mon, Sep 01, 2008 at 04:49:12PM -0400, Paul Wouters wrote: > On Sun, 31 Aug 2008, David Conrad wrote: > > > 5. I suspect having encryption will make getting export licenses more > > complicated. > > 6. Ellipctic Curve is patent encumbered Perhaps http://cr.yp.to/ecdh/patents.html can shed s

Re: [DNSOP] I think we may have a solution - DNSCurve

2008-09-01 Thread Paul Wouters
On Sun, 31 Aug 2008, David Conrad wrote: > 5. I suspect having encryption will make getting export licenses more > complicated. 6. Ellipctic Curve is patent encumbered Without seeing an RFC style protocol description, it is hard to see how completely thought out this proposal is, but I think t

[DNSOP] I-D Action:draft-ietf-dnsop-reflectors-are-evil-06.txt

2008-09-01 Thread Internet-Drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Domain Name System Operations Working Group of the IETF. Title : Preventing Use of Recursive Nameservers in Reflector Attacks Author(s) : J. Damas, F.

Re: [DNSOP] Anycast was Re: Cache poisoning on DNSSEC

2008-09-01 Thread Ralf Weber
Moin! On Aug 30, 2008, at 22:48 , Dean Anderson wrote: >> While I get paid for that it does work four our customers, so this >> obviously this is my first concern. > > I doubt that many of your customers use TCP DNS. Correct, but we do see in total an average of 5 to 10 TCP clients per second. S