Re: djbdns/dnscache poisoning weakness
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 12 Feb 2009, Michael Sierchio wrote: > Dean Anderson wrote: > > > The fear factor is in the 'just repeat and you'll succeed eventually'. > > This is true, just not realistic. > > > > If you want very secure DNS, use TCP. > > That doesn't work -- a TCP-based DNS, as currently conceived, cannot > scale. Prof. Bernstein has made lucid and cogent remarks on this subject > already. Actually, it turns out that Dan Kaminsky wrote a fast TCP scanner that bypassed the unix TCP stack. TCP can scale. Just not with the file descriptor abstraction. --Dean -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 344 9000