<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Internet Engineers to Congress: SOPA censorship will harm Internet&#160;security</title>
	<atom:link href="http://boingboing.net/2011/12/15/internet-engineers-to-congress.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Fri, 24 May 2013 08:44:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Guest</title>
		<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html#comment-1298771</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Fri, 16 Dec 2011 18:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=134422#comment-1298771</guid>
		<description>OK, so a SOPA blocked site in DNS returns a false response and DNSSEC shows the response has been tampered with.

That is exactly what has happened, and the results are what you would expect. You don&#039;t use the response and you don&#039;t get to the site.

I don&#039;t see how SOPA is a good idea, but I don&#039;t see how it interferes with DNSSEC if the goal is to prevent blocked sites from resolving.</description>
		<content:encoded><![CDATA[<p>OK, so a SOPA blocked site in DNS returns a false response and DNSSEC shows the response has been tampered with.</p>
<p>That is exactly what has happened, and the results are what you would expect. You don&#8217;t use the response and you don&#8217;t get to the site.</p>
<p>I don&#8217;t see how SOPA is a good idea, but I don&#8217;t see how it interferes with DNSSEC if the goal is to prevent blocked sites from resolving.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Bennett</title>
		<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html#comment-1297209</link>
		<dc:creator>Matt Bennett</dc:creator>
		<pubDate>Thu, 15 Dec 2011 16:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=134422#comment-1297209</guid>
		<description>News should be out at 10:30 CE, that&#039;s what I was told.</description>
		<content:encoded><![CDATA[<p>News should be out at 10:30 CE, that&#8217;s what I was told.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ComradeQuestions</title>
		<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html#comment-1297196</link>
		<dc:creator>ComradeQuestions</dc:creator>
		<pubDate>Thu, 15 Dec 2011 15:45:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=134422#comment-1297196</guid>
		<description>Ah, indeed:  http://www.theregister.co.uk/2011/11/20/sopa_breaks_dnssec/

Though it seems at this point, without clients really doing DNSSEC enforcement, ISPs could simply set their resolvers to give NXDOMAIN replies to blacklisted sites without clients caring.  Though that&#039;s certainly not sustainable with the ultimate goal of DNSSEC.

Interesting that legislators didn&#039;t simply put the mandate on domain registrars instead of ISPs.</description>
		<content:encoded><![CDATA[<p>Ah, indeed:  <a href="http://www.theregister.co.uk/2011/11/20/sopa_breaks_dnssec/" rel="nofollow">http://www.theregister.co.uk/2011/11/20/sopa_breaks_dnssec/</a></p>
<p>Though it seems at this point, without clients really doing DNSSEC enforcement, ISPs could simply set their resolvers to give NXDOMAIN replies to blacklisted sites without clients caring.  Though that&#8217;s certainly not sustainable with the ultimate goal of DNSSEC.</p>
<p>Interesting that legislators didn&#8217;t simply put the mandate on domain registrars instead of ISPs.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SaberUK</title>
		<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html#comment-1297180</link>
		<dc:creator>SaberUK</dc:creator>
		<pubDate>Thu, 15 Dec 2011 15:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=134422#comment-1297180</guid>
		<description>DNS blocking is incompatible with DNSSEC.</description>
		<content:encoded><![CDATA[<p>DNS blocking is incompatible with DNSSEC.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ComradeQuestions</title>
		<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html#comment-1297169</link>
		<dc:creator>ComradeQuestions</dc:creator>
		<pubDate>Thu, 15 Dec 2011 15:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=134422#comment-1297169</guid>
		<description>I&#039;d be interested to hear more on how they envision DNS blocking to be a security risk.  I can imagine plenty of secondary issues, like people using insecure DNS that doesn&#039;t block these sites, or sites being blocked which provide security services.  But I can&#039;t think of how the act of simply breaking the DNS resolution of a site can have such dire consequences.  In fact, it&#039;s pretty standard practice for network security people to prevent resolution of malicious domains on their own DNS servers.

Which isn&#039;t to say that these bills are a GOOD idea.  Far from it.  It just seems like they should provide more evidence of these issues, since we&#039;re always complaining about pro-copyright legislation not being evidence-based.</description>
		<content:encoded><![CDATA[<p>I&#8217;d be interested to hear more on how they envision DNS blocking to be a security risk.  I can imagine plenty of secondary issues, like people using insecure DNS that doesn&#8217;t block these sites, or sites being blocked which provide security services.  But I can&#8217;t think of how the act of simply breaking the DNS resolution of a site can have such dire consequences.  In fact, it&#8217;s pretty standard practice for network security people to prevent resolution of malicious domains on their own DNS servers.</p>
<p>Which isn&#8217;t to say that these bills are a GOOD idea.  Far from it.  It just seems like they should provide more evidence of these issues, since we&#8217;re always complaining about pro-copyright legislation not being evidence-based.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: danimagoo</title>
		<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html#comment-1297165</link>
		<dc:creator>danimagoo</dc:creator>
		<pubDate>Thu, 15 Dec 2011 15:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=134422#comment-1297165</guid>
		<description>Something tells me that this will be WAAAYY over the heads of congressmen who mostly still can&#039;t understand what the internet is beyond &quot;a series of tubes.&quot;</description>
		<content:encoded><![CDATA[<p>Something tells me that this will be WAAAYY over the heads of congressmen who mostly still can&#8217;t understand what the internet is beyond &#8220;a series of tubes.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SpaceBeers</title>
		<link>http://boingboing.net/2011/12/15/internet-engineers-to-congress.html#comment-1297152</link>
		<dc:creator>SpaceBeers</dc:creator>
		<pubDate>Thu, 15 Dec 2011 15:04:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=134422#comment-1297152</guid>
		<description>When do we find out the results of this?</description>
		<content:encoded><![CDATA[<p>When do we find out the results of this?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
