On May 31, 2013, at 8:17 AM, Paul Wouters <[email protected]> wrote:
> Whoever designs a security protocol with no crypto algility should take
> up another hobby, something nice like gardening or star gazing.

  dnscrypt supports crypto agility, not by negotiating a cipher suite, but by 
protocol version negotiation.
  The cipher suite it uses has changed twice already.

> On top of that, there is the question of usefulness. You send out an
> encrypted DNS packet for www.secret.com.

  dnscrypt is about authentication, not privacy, and I hope the project 
description (not the opendns marketing page) makes it clear.

  Just fgrep -c "authentic" vs fgrep -c "encrypt" in the description.
  

_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to