[dns-operations] we may finally have a dnssec use case ; -) Re: Odd behaviour of DNS queries in PRC (facebook, youtube & twitter)

Paul Vixie vixie at isc.org
Mon Mar 29 13:14:02 UTC 2010


> From: "George Barwood" <george.barwood at blueyonder.co.uk>
> Date: Mon, 29 Mar 2010 08:07:18 +0100
> 
> >> I second Stephane and previous Bert's opinion.
> > 
> > Given the nature of why this is happening, this is one of the first
> > usecases I see for DNSSEC that actually is worth the administrative
> > overhead.
> 
> I don't think DNSSEC stops this attack. It is (I think) a selective
> Denial of Service attack.  The way to prevent attacks like this is to
> encrypt and authenticate packets, ...

you are absolutely wrong on both counts.



More information about the dns-operations mailing list