Re: squirting spray foam into the crack at the bottom of the BAW
Maciej Żenczykowski <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
> One only needs to fall back to TCP in that case. An attacker in the > path would be able to spoof in one packet, most of the time. So if we > detect a birthday attack, then we know the attacker isn't in the path. > And TCP is more than sufficient to prevent attacks from attackers who > are not in the path. True, although DNS servers which know their responses will not exceed 512 bytes (or whatever that number is) are not required to actually support TCP (or at least in practice often don't).