From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from uplift.swm.pp.se (ipv6.swm.pp.se [IPv6:2a00:801::f]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by huchra.bufferbloat.net (Postfix) with ESMTPS id 1DD1521F3D1 for ; Fri, 9 May 2014 01:38:47 -0700 (PDT) Received: by uplift.swm.pp.se (Postfix, from userid 501) id 73722A1; Fri, 9 May 2014 10:38:43 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=swm.pp.se; s=mail; t=1399624723; bh=aw4VwUg5ve2LDXReszKQKdAUIHro+KwuKSiy2l43SBE=; h=Date:From:To:cc:Subject:In-Reply-To:References:From; b=4xI8sZO++luzso9px05rzaDybpElMkLqxrBjePARAk13THwjdgcNm3cfwW67vVDwI d98W322xMSv9tDtVk4ipZ85H9CnQf6OOtH4lLCtYzLirDtxw6Q2P3HH83ZxgvACkqF VUkAz6OyRFa1fYSmciB+PaLxsMvbGX0USEhTiCUI= Received: from localhost (localhost [127.0.0.1]) by uplift.swm.pp.se (Postfix) with ESMTP id 6C33B9C; Fri, 9 May 2014 10:38:43 +0200 (CEST) Date: Fri, 9 May 2014 10:38:43 +0200 (CEST) From: Mikael Abrahamsson To: Maciej Soltysiak In-Reply-To: Message-ID: References: User-Agent: Alpine 2.02 (DEB 1266 2009-07-14) Organization: People's Front Against WWW MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed Cc: "cerowrt-devel@lists.bufferbloat.net" Subject: Re: [Cerowrt-devel] "DNSSEC considered harmful" X-BeenThere: cerowrt-devel@lists.bufferbloat.net X-Mailman-Version: 2.1.13 Precedence: list List-Id: Development issues regarding the cerowrt test router project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 09 May 2014 08:38:48 -0000 On Thu, 8 May 2014, Maciej Soltysiak wrote: > Hi, > > I read a twitter conversation last night where somebody said DNSSEC is > harmful. I asked why and I got this littany of issues: > http://ianix.com/pub/dnssec-outages.html > > I was blown away not only by the sheer evidence of outages, but especially > by the quotes in last sections: Miscellaneous and What a mess. > > I don't know, have a look, I just wanted to share as I wasn't aware of > things that didn't go well with DNSSEC. I'm not suggesting anything re > Cerowrt here. The failure mode of encrypted and authenticated communications is catastrophic failure (=nothing works). There are plenty people who says the "proceed anyway" option in modern browsers when the certificate failures occur, is wrong and the user shouldn't be allowed to continue. This is why security is so hard, because secsurity protects against a potential and unknown attack, whereas when it doesn't work, you fail completely and the user just wants things to work so they'd rather turn security off and proceed anyway. -- Mikael Abrahamsson email: swmike@swm.pp.se