TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Paul Vixie: Whither DNSCurve? [2010]

3 pointsby sadplutoalmost 13 years ago

1 comment

sadplutoalmost 13 years ago
Could security experts give their take on this? There are some strong statements, such as the last sentence: "Because DNSCurve does not do this, and because the problems DNSCurve actually does solve are pretty well solved by UDP source port randomization and will be entirely eradicated by DNSSEC, ISC is not investing in DNSCurve at all."<p>I have a few questions, in case anybody is interested in any of them:<p>1) Would full deployment of IPsec render DNSCurve unnecessary?<p>2) Isn't "full security" impossible until DNS queries are encrypted? I'm reading the ongoing comments about HSTS [+] and can't help to think that, if you assume the network is a malicious medium, then any unencrypted DNS query, <i>including DNSSEC</i>, can receive a compromised response. But then again, Paul Vixie's quoted sentence seems to counter my reasoning/understanding.<p>[+] <a href="http://news.ycombinator.com/item?id=4266626" rel="nofollow">http://news.ycombinator.com/item?id=4266626</a>
评论 #4268731 未加载