Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> delegate security to higher layers so that there's not much point in bothering to poison it. Literally, my answer is DO NOTHING NEW.

That would not help my server - the DNS poisoning is acting like a DDOS. Sure the random victims know they are on the wrong page, but it doesn't help my server for them to know that.



Isn't exactly the same form of DDOS --- not even reaching how many simpler ways there are to DDOS you --- available in DNSSEC, by injecting non-validating records?


Not exactly, as you don't cache non validating records (for very long).


Wonder if DNSCurve would solve that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: