[dns-operations] Bloke takes over every .io domain by snapping up crucial name servers

James Stevens James.Stevens at jrcs.co.uk
Tue Jul 11 14:00:16 UTC 2017


Very interesting

The Address records, for the dot-IO NS sent in the "ADDITIONAL" section 
by the ROOT server, surely have the status of GLUE records.

Are these not ever verified with an NS server of dot-IO itself to get 
the correct AUTHORITATIVE data? And at that point wouldn't the NS server 
for dot-IO respond with the delegation instead of the Address records?

Would this also not be a requirement for verification of a signed zone - 
in order to get the RRSIG records?


On 11/07/17 14:29, Ray Bellis wrote:
> On 11/07/2017 14:13, James Stevens wrote:
> 
>> oh dear.
> 
> Or not:
> 
> http://mpounsett.blogspot.co.uk/2017/07/the-io-error-problem-with-bad-optics.html
> 
> Ray
> 
> _______________________________________________
> dns-operations mailing list
> dns-operations at lists.dns-oarc.net
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations
> dns-operations mailing list
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations
> 



More information about the dns-operations mailing list