Re: [DNSOP] [dns-privacy] DNS stamps

2020-01-10 Thread Ted Lemon
On Jan 10, 2020, at 9:45 AM, Dan Wing wrote: > The signature could be retrieved and validated separately from the stamp > itself. For example, after getting the DNS stamp, retrieve a well-known DNS > object (TXT, new RR, whatever) which is signed by the external entity. That > would keep the

Re: [DNSOP] [dns-privacy] DNS stamps

2020-01-10 Thread Dan Wing
On Jan 9, 2020, at 10:22 AM, Vladimír Čunát wrote: > I see a bigger problem that some of desired assertions are in principle > unverifiable, e.g. "no logging". Of course, we could (optionally) extend the > string by a signature, but I suspect that'd increase the length a lot without > sufficie