Re: [DNSOP] [Ext] "The Forgotten Object Lesson Of The Dyn DDoS Attack"

2019-01-03 Thread Steve Crocker
Weighing in on this, I think this is an important piece of work. I’m particularly interested in what else is necessary to introduce the multiple dns operators to each, to authorize their cooperation, and facilitate cross signing of keys whenever a new operator is introduced and whenever one or

Re: [DNSOP] [Ext] "The Forgotten Object Lesson Of The Dyn DDoS Attack"

2019-01-03 Thread Tim Wicinski
Actually draft-huque-dnsop-multi-provider-dnssec was adopted, but the author (whom I work with and has heard from me about this regularly) has failed to push up an updated version. I'm going to force him to turn the authorship over to one of the other authors who is more responsive to the needs

Re: [DNSOP] [Ext] "The Forgotten Object Lesson Of The Dyn DDoS Attack"

2019-01-03 Thread Paul Hoffman
On Jan 3, 2019, at 5:02 AM, Töma Gavrichenkov wrote: > If I were to trace that through the recent DNSOP activity, I could > bring up my own draft (draft-gavrichenkov-dnsop-dnssapi), also not > adopted and now expired. Maybe there were discussions of the same > sort before me that I'm not aware of

Re: [DNSOP] "The Forgotten Object Lesson Of The Dyn DDoS Attack"

2019-01-03 Thread Töma Gavrichenkov
On Thu, Jan 3, 2019 at 2:03 PM Stephane Bortzmeyer wrote: > I believe Cricket Liu refers to draft-woodworth-bulk-rr Certainly not. See https://portswigger.net/daily-swig/middle-aged-dns-tech-still-has-legs-to-kick-on from the same author where the idea is explained kind of better: "The challeng

[DNSOP] "The Forgotten Object Lesson Of The Dyn DDoS Attack"

2019-01-03 Thread Stephane Bortzmeyer
https://www.forbes.com/sites/forbestechcouncil/2018/12/19/the-forgotten-object-lesson-of-the-dyn-ddos-attack/ This article talks about "There have been discussions within the Internet Engineering Task Force, the organization responsible for developing and enhancing internet protocols, to come up w