This is a great talk; Bernstein is a surprisingly excellent public speaker with solid timing. You can get most of the points he raises from the foils of previous talks on his website, but, the high points: * DNSSEC offers DDoS attackers 30+ : 1 amplification for attack traffic; at reasonably low deployment levels, it allows a 200> node botnet to saturate most websites on the Internet. It does this while not actually…
> Your conception of the speed of public-key crypto is warped by how slow SSL is; 256 bit elliptic curve crypto, which hasn't degraded in security for almost 25 years, is so fast that you can rekey 10 million sessions every 10 minutes on standard PC hardware. This argument implies ECC and SSL are mutually exclusive when they aren't. ECC has been a standardized part of SSL for years and there are many shipping impleme…
Yeah, this is definitely an apples to apples standard compared to what DNSSEC dealt with.
I am, for the record, (a) a proponent of x509 and (in particular) TLS, (b) not a particular fan of "nym security", (c) not optimistic about any ground-up replacement of TCP. It's weird that you're arguing with me about this stuff.
But he's straight-up right about DNS security.