[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [idn] New protocol proposal: IDNRA



% Personally, based on the deployment time for the DNS itself --
% despite occurring in a much smaller network where the possibility
% of central control existed-- I think Patrik is being wildly
% optimistic, probably by a factor of two, rather than just a year
% or so.   Deploying a new application is, due to the nature of the
% Internet and the end to end principle, fairly easy.   Upgrading
% one has proven to be much harder (e.g., MIME and the SMTP
% extensions offered a lot to users, but I'd guess we are still
% well under 90% penentration of competent and conforming
% implementations nearly seven years out).  And changing
% infrastructure --and the DNS and its protocols is certainly
% infrastructure-- is much worse, since both the servers/resolvers
% and the applications need to be upgraded.  Now, of course, if it
% is possible to deploy the new mechanisms without changing
% _anything_, more rapid estimates become feasible.  Maybe only a
% decade or so :-(
% 
%     john

	We have some metrics on diffusion rates of new code
	in the DNS.  If significant vulnerabilities exist,
	they are generally mitigated in about 18 months, at least
	based on current data.



-- 
--bill