[Top] [All Lists]

Re: DNSCurve vs. DNSSEC - FIGHT! (was OpenDNS today announced it has adopted DNSCurve to secure DNS)

2010-02-24 20:10:17
Nikos Mavrogiannopoulos wrote:

Not really. I Don't know what you mean by simple nonce, but as I
understand dnscurve if implemented properly would have ssh-style

Ssh without secure public key distribution mechanism is not really
secure cryptographically.

In general, public key cryptography is scure only if public key
distribution is secure.

For example, DNSSEC is not really secure because key distribution
through trusted third parties is not really trustable.

Only the first request of the server key is vulnerable
with mitm.

So, we agree that DNSCurve is valunerable to MitM attacks.

Then it should be cached.

As it is cached, a successful attack on the first request, which
is easy if you can snoop packets, is more than enough.

It invalidate all the legitimate replies and validate all the
forged replies.

If you can't snoop packets, long message ID is just secure.

                                                Masataka Ohta

Ietf mailing list

<Prev in Thread] Current Thread [Next in Thread>