Re: squirting spray foam into the crack at the bottom of the BAW

Hugo Monteiro <[email protected]>
Newsgroups gmane.network.djbdns
Message-ID <[email protected]>
On 03/16/2010 01:18 AM, Maciej Żenczykowski wrote:
>> One only needs to fall back to TCP in that case.  An attacker in the
>> path would be able to spoof in one packet, most of the time.  So if we
>> detect a birthday attack, then we know the attacker isn't in the path.
>> And TCP is more than sufficient to prevent attacks from attackers who
>> are not in the path.
>>      
> True, although DNS servers which know their responses will not exceed
> 512 bytes (or whatever that number is) are not required to actually
> support TCP (or at least in practice often don't).
>
>    


 From what i understood, that's exactly Dean point. DNS servers would 
fallback to TCP if:

1 - Responses were larger than 512 bytes (as described in the current RFC).
2 - When they felt threatened by a birthday attack.

R's,

Hugo Monteiro.

-- 
fct.unl.pt:~# cat .signature

Hugo Monteiro
Email	 : [email protected]
Telefone : +351 212948300 Ext.15307
Web      : http://hmonteiro.net

Divisão de Informática
Faculdade de Ciências e Tecnologia da
		   Universidade Nova de Lisboa
Quinta da Torre   2829-516 Caparica   Portugal
Telefone: +351 212948596   Fax: +351 212948548
www.fct.unl.pt                [email protected]

fct.unl.pt:~# _
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.