Re: squirting spray foam into the crack at the bottom of the BAW
Dean Anderson <[email protected]>
| Newsgroups | gmane.network.djbdns |
|---|---|
| Message-ID | <[email protected]> |
Name some that don't support TCP. You are aware the the IETF is now moving to make TCP required, when it used to be optional for non-public service operators. --Dean *Public service dns operators are: root, TLD and ccTLD operators. On Mon, 15 Mar 2010, [UTF-8] Maciej à »enczykowski wrote: > > One only needs to fall back to TCP in that case. àAn attacker in the > > path would be able to spoof in one packet, most of the time. àSo if we > > detect a birthday attack, then we know the attacker isn't in the path. > > And TCP is more than sufficient to prevent attacks from attackers who > > are not in the path. > > True, although DNS servers which know their responses will not exceed > 512 bytes (or whatever that number is) are not required to actually > support TCP (or at least in practice often don't). > > -- Av8 Internet Prepared to pay a premium for better service? www.av8.net faster, more reliable, better service 617 256 5494