3 ms·
> I haven't heard many alternatives (in general). These problems don't call for a general solution. We should respect the fundamental truth behind the end-to-
by secalex 12y ago
> I haven't heard many alternatives (in general).
These problems don't call for a general solution. We should respect the fundamental truth behind the end-to-end principle and solve these problems as close to the application as possible. The likely threats, appropriate default choices and trust model are all best understood by each application developer and building these solutions into Layer-3/4 is bound to cause short-term pain and reduce our long-term flexibility to meet new risks.
For example, EFF's STARTTLS Everywhere project takes into account the fact that a huge percentage of the world's mail moves between a small enough number of providers that human verification of announcements is possible. It also recognizes that the MX configuration for these providers is reasonably static, meaning that changes that propagate in minutes do not need to be accommodated. Small specific solutions like this can be rolled out and provide a real, tangible benefit to users much faster than we can upgrade the entire DNS system to provide a more general solution.
I agree that we need a DNS privacy solution, one that hopefully doesn't eliminate the existence of caching infrastructure.
- danyork 12y ago> I agree that we need a DNS privacy solution, one that hopefully doesn't eliminate the existence of caching infrastructure. Please do take a look at what the folks are doing within the DPRIVE working group of the IETF: https://datatracker.ietf.org/wg/dprive/charter/ https://datatracker.ietf.org/wg/dprive/charter/ They are working on mechanisms to bring privacy / confidentiality to the "last mile" of DNS connections. Any input you have would be useful. (There's a link there to a mailing list to which you can subscribe.)