[dns-operations] Media coverage of amplification attacks opening pandoras box?

Florian Weimer fw at deneb.enyo.de
Sat Mar 25 18:58:12 UTC 2006


* Randy Bush:

>> These documents describing what exactly it is and how to do it, did we
>> just teach 50 more of these kids who arent bright enough to think out
>> of the box like this one individual did?
>
> yes.  security through obscurity does not work very well.

There's quite a bit of empirical evidence that delaying disclosure
also delays exploitation.  And given enough delay, we might have
implemented network-wide changes which address the BCP38 issue, for
instance.



More information about the dns-operations mailing list