On Iau, 2003-07-10 at 01:53, David Boyes wrote: > If you've poisoned the DNS from the outside (ie, both hosts consult an > corrupted outside DNS), then encrypting the data isn't any real defense > either -- you need connection authentication; whether the data is encrypted > or not isn't the issue, it's whether you recognize your peer that counts. > Not really the same problem, although linked.
Its a defence because your encryption keys are not tied to DNS. Yes you stole my data, no you can't read it > I don't deny that encryption is *good*. The question was whether it is > *necessary* in an environment where most of the common attacks you mention > are difficult or impossible to perform if the administrator is even > moderately alert. I guess you have more faith in your administrator's powers than me.
