From mboxrd@z Thu Jan 1 00:00:00 1970 MIME-Version: 1.0 In-Reply-To: References: <4B57048D.6040002@maht0x0r.net> <4f34febc1001231559s3ffb6037o2a193bf4689b961@mail.gmail.com> Date: Sat, 23 Jan 2010 16:52:14 -0800 Message-ID: Subject: Re: [9fans] Are we ready for DNSSEC ? From: Russ Cox To: Fans of the OS Plan 9 from Bell Labs <9fans@9fans.net> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Topicbox-Message-UUID: c5948556-ead5-11e9-9d60-3106f5b1d025 > so if you're interested in securing dns, say to prevent ssl > mitm attacks, i only see three choices > 1. =C2=A0hold your nose. =C2=A0do dnssec. > 2. =C2=A0put your head in the sand. > 3. =C2=A0convince the world to use dnscurve. if the goal is avoiding ssl mitm attacks, dns is the least of your worries. a mitm will just take over the connection attempt for the actual ip address. the solution there is to implement proper ssl certificate chain checking. russ