[dns-operations] Just another "sitefinder" ISP

David Conrad drc at virtualized.org
Thu May 22 14:13:37 UTC 2008


On May 22, 2008, at 4:06 AM, Florian Weimer wrote:
> Kabel Deutschland
> makes it non-transparent, currently on the customer's entry point to  
> the
> DNS network.
...
> Using magic addresses for the root servers would only encourage such
> tampering.  So I agree that it's not a good idea.

Again, the root server addresses are already well known and must be.   
Locking down those addresses so that we don't have to deal with  
traffic going to "old root server" addresses is completely orthogonal  
to the fact that some caching server operators have decided to muck  
with the data they serve.

Regards,
-drc




More information about the dns-operations mailing list