[106258] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Exploit for DNS Cache Poisoning - RELEASED

daemon@ATHENA.MIT.EDU (David Conrad)
Thu Jul 24 20:44:42 2008

From: David Conrad <drc@virtualized.org>
To: "Tomas L. Byrnes" <tomb@byrneit.net>
In-Reply-To: <70D072392E56884193E3D2DE09C097A9F3B6@pascal.zaphodb.org>
Date: Thu, 24 Jul 2008 17:43:10 -0700
Cc: nanog@merit.edu
Errors-To: nanog-bounces@nanog.org

On Jul 24, 2008, at 4:24 PM, Tomas L. Byrnes wrote:
> The problem is, once the ICANNt root is self-signed, the hope of ever
> revoking that dysfunctional mess as authority is gone.

Sorry, I don't follow -- sounds like FUD to me.  Care to explain this?

As far as I'm aware, as long as the KSK isn't compromised, changing  
the organization who holds the KSK simply means waiting until the next  
KSK rollover and have somebody else do the signing.

> Perhaps the IETF

You mean oh say IANA?

> or DoC

That'll be popular in the international community.

> should sign the root, that way we have a prayer
> of wresting control from ICANN, as opposed to paying a tax, in

> perpetuity, for registration services to an unaccountable, unelected,
> and imperious body?

Registration fees are unrelated to signing the root, but thanks for  
the gratuitous ICANN bashing.  It was missing in this thread -- I was  
wondering when it would show up.

> Some of us don't think the UN/EU/ITU are good models for governance.

Indeed.

> IE: Separation of powers. ICANN/IANA is granted (interim) authority to
> operate, but some other governing body signs.


So you want to increase the role ICANN/IANA has in root zone  
management.  Interesting.

Regards,
-drc



home help back first fref pref prev next nref lref last post