Live data from Hacker News

Measuring open DNS resolver use

blog.apnic.net

51–53 of 53 posts

Re: Measuring open DNS resolver use

#51
post #49

Earlier quoted context omitted.

If my iPhone honored my passphrase, but also a second secret passphrase held by Apple in iCloud that I had no control over, what would you call that scheme? I would say that Apple had an escrowed passphrase. Well, that's precisely how DNSSEC works. I control my own key, sure, and never have to reveal it, but that doesn't matter, because the roots can simply override that key with their own. You keep making these emot…

At the risk of wasting my time with Humpty Dumpty: OK, so first up I guess the problem is you've no idea what "escrow" is and so you ended up confused as to what key escrow could be. So let's fix that first. Escrow is a service people or companies offer, the idea goes like this. Alice wants to do a deal with Bob, and Bob wants to make a deal with Alice, they're going to swap some of Alice's baseball cards for Bob's a…

If you'd prefer to refer to DNSSEC as a "backdoored" crypto protocol, I'm happy to stipulate that here.

Saying that backdoors are "the whole _point_" of a cryptosystem is not the devastating refutation you appear to think it is.

Re: Measuring open DNS resolver use

#52
post #51

Earlier quoted context omitted.

At the risk of wasting my time with Humpty Dumpty: OK, so first up I guess the problem is you've no idea what "escrow" is and so you ended up confused as to what key escrow could be. So let's fix that first. Escrow is a service people or companies offer, the idea goes like this. Alice wants to do a deal with Bob, and Bob wants to make a deal with Alice, they're going to swap some of Alice's baseball cards for Bob's a…

If you'd prefer to refer to DNSSEC as a "backdoored" crypto protocol, I'm happy to stipulate that here. Saying that backdoors are "the whole _point_" of a cryptosystem is not the devastating refutation you appear to think it is.

You got into this saying DNSSEC "essentially" does key escrow and you've now walked this back to a stipulation that the whole point of all PKI is a "backdoor".

But that goes from being a relevant point about Vixie (his support of a system with key escrow - a false claim) to the irrelevant and vague (trusted people might betray your trust) that I guess if I squint I could read as sort of vague anti-establishment sentiment and otherwise is just pointless.

Here's a much shorter way to write what you meant without needing to slip in a false claim about DNSSEC:

"Paul Vixie is a smart guy but he's wrong about this"

Re: Measuring open DNS resolver use

#53
post #51

Earlier quoted context omitted.

If you'd prefer to refer to DNSSEC as a "backdoored" crypto protocol, I'm happy to stipulate that here. Saying that backdoors are "the whole _point_" of a cryptosystem is not the devastating refutation you appear to think it is.

You got into this saying DNSSEC "essentially" does key escrow and you've now walked this back to a stipulation that the whole point of all PKI is a "backdoor". But that goes from being a relevant point about Vixie (his support of a system with key escrow - a false claim) to the irrelevant and vague (trusted people might betray your trust) that I guess if I squint I could read as sort of vague anti-establishment senti…

If you want to acknowledge that this is a totally pointless semantic argument, I'm right there with you, but you're the one who prosecuted that argument, not me.
Post reply on HN