[dns-operations] Can Root DNS server modify the response?

Ondřej Surý ondrej at sury.org
Mon Mar 25 15:36:27 UTC 2019


For a *censorship* purposes, there’s no difference between not getting an answer or not getting an answer.

As much as I love DNSSEC, it doesn’t prevent censorship implemented as DoS.

Ondřej 
--
Ondřej Surý <ondrej at sury.org>

On 25 Mar 2019, at 16:18, Viktor Dukhovni <ietf-dane at dukhovni.org> wrote:

>> On Mar 25, 2019, at 10:56 AM, Ondřej Surý <ondrej at sury.org> wrote:
>> 
>> Matt, there’s no difference between NXDOMAIN and SERVFAIL from the client perspective.
> 
> Actually, there is for DANE, SPF, Kerberos domain to realm mappings, ...
> but TLDs are not usually in scope for this type of query.
> 
> [ The DNS is not *just* for web browsing ]
> 
> -- 
>    Viktor.
> 
> 
> _______________________________________________
> dns-operations mailing list
> dns-operations at lists.dns-oarc.net
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations
> dns-operations mailing list
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations




More information about the dns-operations mailing list