[116529] in North American Network Operators' Group
Re: dnscurve and DNS hardening, was Re: Dan Kaminsky
daemon@ATHENA.MIT.EDU (Tony Finch)
Thu Aug 6 08:49:17 2009
Date: Thu, 6 Aug 2009 13:48:56 +0100
From: Tony Finch <dot@dotat.at>
To: Naveen Nathan <naveen@calpop.com>
In-Reply-To: <20090806020524.GK30683@armakuni.lastninja.net>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Wed, 5 Aug 2009, Naveen Nathan wrote:
>
> I might misunderstand how dnscurve works, but it appears that dnscurve
> is far easier to deploy and get running.
Not really. There are multiple competing mature implementations of DNSSEC
and you won't be in a network of 1 if you deploy it.
Tony.
--
f.anthony.n.finch <dot@dotat.at> http://dotat.at/
GERMAN BIGHT HUMBER: SOUTHWEST 5 TO 7. MODERATE OR ROUGH. SQUALLY SHOWERS.
MODERATE OR GOOD.