Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Beta Programs
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
"One-Character Patch" for DNS? Not so fast
Robert Lemos,
2008-08-29
Comments
Mode:
Threaded
Flat
Expand all
|
Post comment
"One-Character Patch" for DNS? Not so fast
2008-09-01
Gabriel Somlo
I have been available for comment since Friday
night, but an update containing my response
has yet to be posted.
I take issue with Dan Kaminsky's fixation on
the necessity of forcing operators of caching
servers everywhere to accept unscheduled changes
(i.e. before the TTLs of the original records
they hold expire) from authoritative domains.
I believe this should be left as a choice each
operator makes by turning a configuration option
on or off: ignore unscheduled updates to reduce
their attack surface, or accept them for faster
convergence in case of unscheduled changes made
by important domain operators who lack redundancy
or forethought...
[ reply ]
Link to this comment:
http://www.securityfocus.com/comments/newsbriefs/808/2587#2587
Privacy Statement
Copyright 2009, SecurityFocus
night, but an update containing my response
has yet to be posted.
I take issue with Dan Kaminsky's fixation on
the necessity of forcing operators of caching
servers everywhere to accept unscheduled changes
(i.e. before the TTLs of the original records
they hold expire) from authoritative domains.
I believe this should be left as a choice each
operator makes by turning a configuration option
on or off: ignore unscheduled updates to reduce
their attack surface, or accept them for faster
convergence in case of unscheduled changes made
by important domain operators who lack redundancy
or forethought...
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/newsbriefs/808/2587#2587