On Wed, Mar 25, 2015 at 02:34:01PM -0400, Paul Wouters wrote:
> If the lookup service is on port X, and the attacker blocks port X, you
> do not know whether there is a service interruption or an active attack.

How is that different from the attacker blocking DNS?

> Any lookup mechanism must remain within the DNS.

This lookup service would be like an extension of DNS.

_______________________________________________
dane mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dane

Reply via email to