Re: squirting spray foam into the crack at the bottom of the BAW
Joe Baptista <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
That would be nice - a DNS with IDS - especially if IDS was specialized for DNS. Good idea. regards joe baptista On Sat, Mar 13, 2010 at 10:09 PM, David Nicol <[email protected]> wrote: > On Fri, Mar 12, 2010 at 3:48 PM, Dean Anderson <[email protected]> wrote: > > server. Like I said before, an IDS should detect a 26 million packet > > attack before it succeeds. DJB has said something similar. > > > > [...] > > > > There is no way that the "birthday attack window" can be closed, > > Safety currently appears to require an Intrusion Detection System, so > building > an IDS into a resolver (as has been done, see > http://marc.info/?l=djbdns&m=124356186626355 > ) might be considered the equivalent of squirting some expanding foam > into the crack at the bottom of the window in question. > > What additional measures? second, third, fourth opinions from other > servers presumably not under the same attack, reached over VPN links. > Build that into something, a network of resilient dns servers that > create a mesh of secure tcp links between each other and start > chatting over them when something appears amiss? > -- Joe Baptista www.publicroot.org PublicRoot Consortium ---------------------------------------------------------------- The future of the Internet is Open, Transparent, Inclusive, Representative & Accountable to the Internet community @large. ---------------------------------------------------------------- Office: +1 (360) 526-6077 (extension 052) Fax: +1 (509) 479-0084 Personal: http://baptista.cynikal.net/