[dns-operations] the zone enumeration "show stopper"

Jim Reid jim at rfc1035.com
Mon Mar 6 22:51:35 UTC 2017


> On 6 Mar 2017, at 21:25, Mark Andrews <marka at isc.org> wrote:
> 
> In reality you can't prevent tlds being enumerated for active domains.

Indeed. I said that at the time too. But we ended up with DNSSEC-ter regardless. IMO this was/is utterly pointless security theatre. Sigh.





More information about the dns-operations mailing list