Re: squirting spray foam into the crack at the bottom of the BAW
Hugo Monteiro <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
On 03/16/2010 01:18 AM, Maciej Żenczykowski wrote: >> One only needs to fall back to TCP in that case. An attacker in the >> path would be able to spoof in one packet, most of the time. So if we >> detect a birthday attack, then we know the attacker isn't in the path. >> And TCP is more than sufficient to prevent attacks from attackers who >> are not in the path. >> > True, although DNS servers which know their responses will not exceed > 512 bytes (or whatever that number is) are not required to actually > support TCP (or at least in practice often don't). > > From what i understood, that's exactly Dean point. DNS servers would fallback to TCP if: 1 - Responses were larger than 512 bytes (as described in the current RFC). 2 - When they felt threatened by a birthday attack. R's, Hugo Monteiro. -- fct.unl.pt:~# cat .signature Hugo Monteiro Email : [email protected] Telefone : +351 212948300 Ext.15307 Web : http://hmonteiro.net Divisão de Informática Faculdade de Ciências e Tecnologia da Universidade Nova de Lisboa Quinta da Torre 2829-516 Caparica Portugal Telefone: +351 212948596 Fax: +351 212948548 www.fct.unl.pt [email protected] fct.unl.pt:~# _