Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Masataka Ohta
Tony Finch wrote: I have the beginnings of a solution to this problem. It is based on using tlsdate, which gets the time from a server with minimal risk of interference by a man-in-the-middle. TLS is another PKI and is inherently insecure as CAs can be compromised. As David Conrad wrote in

Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Masataka Ohta
Hi, Hosnieh, Do you think it will be relevant to this document or it can be another informational document only discuss about the vulnerabilities of cryptographic algorithms? As I said, it is a known vulnerability. That is, we don't need a generic new document very much. However, Snowden

Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Evan Hunt
On Fri, Nov 01, 2013 at 03:29:12PM +0900, Masataka Ohta wrote: TLS is another PKI and is inherently insecure as CAs can be compromised. True, but Tony's quorum-based approach could be made exhaustive enough that the adversary would have to have compromised *every* CA. If they can do that, I'm

Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Tony Finch
On 1 Nov 2013, at 06:35, Evan Hunt e...@isc.org wrote: On Fri, Nov 01, 2013 at 03:29:12PM +0900, Masataka Ohta wrote: TLS is another PKI and is inherently insecure as CAs can be compromised. True, but Tony's quorum-based approach could be made exhaustive enough that the adversary would

Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Nicholas Weaver
On Nov 1, 2013, at 7:57 AM, Derek Atkins de...@ihtfp.com wrote: It is unclear to me that ECC as a generic technology is bad, although any specific curves creates by NIST/NSA are certainly suspect. Having said that, Dual-EC-DRBG is a Random Number Generator, not a Hash, Public Key, or Cipher

Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Derek Atkins
Masataka Ohta mo...@necom830.hpcl.titech.ac.jp writes: Hi, Hosnieh, Do you think it will be relevant to this document or it can be another informational document only discuss about the vulnerabilities of cryptographic algorithms? As I said, it is a known vulnerability. That is, we don't

Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Derek Atkins
Nicholas Weaver nwea...@icsi.berkeley.edu writes: On Nov 1, 2013, at 7:57 AM, Derek Atkins de...@ihtfp.com wrote: It is unclear to me that ECC as a generic technology is bad, although any specific curves creates by NIST/NSA are certainly suspect. Having said that, Dual-EC-DRBG is a Random

Re: [DNSOP] [dnsext] DNS vulnerabilities

2013-11-01 Thread Masataka Ohta
Derek Atkins wrote: However, Snowden taught us that we must avoid any fancy cryptography strongly promoted by NIST, including all the EC related ones, which may be documented somewhere. It is unclear to me that ECC as a generic technology is bad, although any specific curves creates by