[dns-operations] maybe a dumb idea on how to fix the dnsproblems

Barry Raveendran Greene bgreene at senki.org
Sun Aug 10 15:46:48 UTC 2008


 

> there are plenty of server farms behind load balancers etc 
> would would have to spend some capital to add TCP.  

Behind load balancers for which function? Break the functions apart. Use
load balancers for resolvers to communicate with you. This whole attack
vector is NOT about the path between the stub resolvers and the recursive
resolver - it is the path between the recursive resolver and the authority.
I see load balancers as a scaling technique for the stub <-> recursive
conversation and on the authority side of the recursive <-> authority
conversation. 

I don't see where the "capital" is required. The two places where you would
need "capital" has economic justifications.








More information about the dns-operations mailing list