ietf-mailsig
[Top] [All Lists]

Re: ] Replay attacks and ISP business models

2005-08-05 01:07:07

On Fri, 5 Aug 2005, william(at)elan.net wrote:

The problem are those user keys. Yes you could use that, but its
incredebly bad for dns stability (this comes back to the whole point
that public keys in dns is bad and user public keys makes it 10x worse)
where as simple A lookups based on unique id in the signature is fairly
low overhead (but it does mean extra dns lookup).

How unique? Per-domain? per-user? per-message? The latter is much worse
than per-user keys.

Tony.
-- 
f.a.n.finch  <dot(_at_)dotat(_dot_)at>  http://dotat.at/
BISCAY: WEST 5 OR 6 BECOMING VARIABLE 3 OR 4. SHOWERS AT FIRST. MODERATE OR
GOOD.

<Prev in Thread] Current Thread [Next in Thread>