[dns-operations] Just another "sitefinder" ISP
drc at virtualized.org
Thu May 22 14:13:37 UTC 2008
On May 22, 2008, at 4:06 AM, Florian Weimer wrote:
> Kabel Deutschland
> makes it non-transparent, currently on the customer's entry point to
> DNS network.
> Using magic addresses for the root servers would only encourage such
> tampering. So I agree that it's not a good idea.
Again, the root server addresses are already well known and must be.
Locking down those addresses so that we don't have to deal with
traffic going to "old root server" addresses is completely orthogonal
to the fact that some caching server operators have decided to muck
with the data they serve.
More information about the dns-operations