ietf
[Top] [All Lists]

Re: [DNSOP] Practical issues deploying DNSSEC into the home.

2013-09-12 13:09:30
On Sep 12, 2013, at 1:49 PM, "Dickson, Brian" 
<bdickson(_at_)verisign(_dot_)com> wrote:
In order to subvert or redirect a delegation, the TLD operator (or
registrar) would need to change the DNS server name/IP, and replace the DS
record(s).

Someone who possesses the root key could in principle create a fake DNS 
hierarchy with relatively few strategic changes, and present it only to certain 
attack targets.   This would be expensive, but not impossible.   It would not 
work, for example, for dragnet-style surveillance.


<Prev in Thread] Current Thread [Next in Thread>