Skip to content

Commit

Permalink
add another security note about what confidentiality guarantees DNSCu…
Browse files Browse the repository at this point in the history
…rve offers
  • Loading branch information
mdempsky committed Feb 27, 2010
1 parent c42ecaf commit b0c9381
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions drafts/draft-dempsky-dnscurve.xml
Expand Up @@ -450,6 +450,12 @@ DNS after a few failed DNSCurve queries. Of course, DNSCurve cannot
make any security guarantees for transactions that do not use
DNSCurve, so clients are encouraged to use DNSCurve if possible.
</t>
<t>
DNSCurve adds some confidentiality by encrypting DNS packet contents
but does not attempt to hide the length of the original DNS packet nor
the source or destination of the packet. Additionally, the TXT format
requires clients to reveal the zone they are querying.
</t>
</section>

<section title='IANA Considerations'>
Expand Down

0 comments on commit b0c9381

Please sign in to comment.