[dns-operations] [Ext] K-root in CN leaking outside of CN

Manu Bretelle chantr4 at gmail.com
Sun Nov 7 23:28:07 UTC 2021


On Sun, Nov 7, 2021 at 1:48 AM Ray Bellis <ray at isc.org> wrote:

>
>
> On 07/11/2021 09:28, Ray Bellis wrote:
>
> > There most certainly were - a similar leak/poison pattern was
> > detected from an I root node hosted in China in March 2010.
>
> and checking our own records, we've had F root servers in China since at
> least 2006.
>
> However we announce our Anycast prefixes "NO_EXPORT" and make it very
> clear that our routes must not propagate beyond the border.


Thanks Ray, that’s useful info.

My original Google searches seemed to indicate that the first root in CN
were quite recent but if did not dig enough.
A colleague pointed me to
https://archive.nanog.org/meetings/nanog53/presentations/Tuesday/Losher.pdf
/
https://bgpmon.net/f-root-dns-server-moved-to-beijing/

Which was about F hosted in China leaking out back in Oct 2011, but Nanog
slides indicate that answers were not rewritten in this case.

Manu

>
>
> Ray
> _______________________________________________
> dns-operations mailing list
> dns-operations at lists.dns-oarc.net
> https://lists.dns-oarc.net/mailman/listinfo/dns-operations
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.dns-oarc.net/pipermail/dns-operations/attachments/20211107/685d9ddf/attachment.html>


More information about the dns-operations mailing list