Re: djbdns/dnscache poisoning weakness
Michael Sierchio <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Dean Anderson wrote: > The fear factor is in the 'just repeat and you'll succeed eventually'. > This is true, just not realistic. > > If you want very secure DNS, use TCP. That doesn't work -- a TCP-based DNS, as currently conceived, cannot scale. Prof. Bernstein has made lucid and cogent remarks on this subject already.