Re: squirting spray foam into the crack at the bottom of the BAW

Joe Baptista <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
That would be nice - a DNS with IDS - especially if IDS was specialized for
DNS. Good idea.

regards
joe baptista

On Sat, Mar 13, 2010 at 10:09 PM, David Nicol <[email protected]> wrote:

> On Fri, Mar 12, 2010 at 3:48 PM, Dean Anderson <[email protected]> wrote:
> > server. Like I said before, an IDS should detect a 26 million packet
> > attack before it succeeds.  DJB has said something similar.
> >
> > [...]
> >
> > There is no way that the "birthday attack window" can be closed,
>
> Safety currently appears to require an Intrusion Detection System, so
> building
> an IDS into a resolver (as has been done, see
> http://marc.info/?l=djbdns&m=124356186626355
> ) might be considered the equivalent of squirting some expanding foam
> into the crack at the bottom of the window in question.
>
> What additional measures? second, third, fourth opinions from other
> servers presumably not under the same attack, reached over VPN links.
> Build that into something, a network of resilient dns servers that
> create a mesh of secure tcp links between each other and start
> chatting over them when something appears amiss?
>



-- 
Joe Baptista

www.publicroot.org
PublicRoot Consortium
----------------------------------------------------------------
The future of the Internet is Open, Transparent, Inclusive, Representative &
Accountable to the Internet community @large.
----------------------------------------------------------------
 Office: +1 (360) 526-6077 (extension 052)
    Fax: +1 (509) 479-0084

Personal: http://baptista.cynikal.net/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.