Re: squirting spray foam into the crack at the bottom of the BAW

Christopher Chan <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
David Nicol wrote:
> On Fri, Mar 12, 2010 at 3:48 PM, Dean Anderson <[email protected]> wrote:
>> server. Like I said before, an IDS should detect a 26 million packet
>> attack before it succeeds.  DJB has said something similar.
>>
>> [...]
>>
>> There is no way that the "birthday attack window" can be closed,
> 
> Safety currently appears to require an Intrusion Detection System, so building
> an IDS into a resolver (as has been done, see
> http://marc.info/?l=djbdns&m=124356186626355
> ) might be considered the equivalent of squirting some expanding foam
> into the crack at the bottom of the window in question.
> 
> What additional measures? second, third, fourth opinions from other
> servers presumably not under the same attack, reached over VPN links.
> Build that into something, a network of resilient dns servers that
> create a mesh of secure tcp links between each other and start
> chatting over them when something appears amiss?

You know that is why dnssec and dnscurve have surfaced right? That there 
is NO WAY that you can secure the DNS protocol as it is right now. The 
question is, what measures shall we take. Modify the DNS protocol or 
take other measures. That is all that is left on the table.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.