On May 31, 2013, at 10:17 PM, Paul Wouters wrote:

> Whoever designs a security protocol with no crypto algility should take up 
> another hobby, something nice like gardening or star gazing.

There's no crypto anything inherent in DNS today, heh.  VPN transport-level 
security is the only option, DNSCrypt being an example of an organic VPN, which 
greatly reduces the barrier to deployment.

There are many drawbacks to it, don't get me wrong.  I just thought it was 
interesting, especially given a) the TCP angle and the benefits thereof and b) 
the additional scaling and other operational drawbacks of SSL, in addition to 
TCP overhead and misfiltering.

-----------------------------------------------------------------------
Roland Dobbins <[email protected]> // <http://www.arbornetworks.com>

          Luck is the residue of opportunity and design.

                       -- John Milton

_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to