This is a good time to look at Bob Frankston's dotDNS proposal [circleid.com] for a layer of reliable but meaningless domain names.
dotDNS lookups can be made self-verifiable using public-key signatures, but without the costly chain of trust required by DNSSEC methods. The validity of a dotDNS binding can be verified easily by the querier, without relying at all on the server that provided the putative binding.
dotDNS does not solve the whole problem, since any layer that translates from humanly meaningful names to dotDNS names is still vulnerable to hijacking. But the reliable and verifiable name bindings in dotDNS will make it much easier to switch name-resolution services when we are dissatisfied with their policies.
dotDNS is a cheap and immediately deployable positive step toward fixing the DNS mess, requiring no approval by any central agency. It's time for a visionary sponsor to step forward and just do it.
There is also an old ICANN Watch discussion of the dotDNS idea [icannwatch.org], under a different name.
|