ietf
[Top] [All Lists]

Re: [DNSOP] Practical issues deploying DNSSEC into the home.

2013-09-12 13:36:09
On Thu, Sep 12, 2013 at 2:07 PM, Ted Lemon 
<Ted(_dot_)Lemon(_at_)nominum(_dot_)com> wrote:

On Sep 12, 2013, at 1:49 PM, "Dickson, Brian" 
<bdickson(_at_)verisign(_dot_)com>
wrote:
In order to subvert or redirect a delegation, the TLD operator (or
registrar) would need to change the DNS server name/IP, and replace the
DS
record(s).

Someone who possesses the root key could in principle create a fake DNS
hierarchy with relatively few strategic changes, and present it only to
certain attack targets.   This would be expensive, but not impossible.   It
would not work, for example, for dragnet-style surveillance.


It would not work for covert dragnet surveillance.

It would work just fine if the attacker did not mind if the surveillance
was detected or actually wanted people to know they were being watched to
intimidate them.

-- 
Website: http://hallambaker.com/
<Prev in Thread] Current Thread [Next in Thread>