[HN Gopher] The CoreDNS Cache Poisoning Conjecture
       ___________________________________________________________________
        
       The CoreDNS Cache Poisoning Conjecture
        
       Author : sbudella
       Score  : 50 points
       Date   : 2023-03-09 13:23 UTC (2 days ago)
        
 (HTM) web link (sbudella.altervista.org)
 (TXT) w3m dump (sbudella.altervista.org)
        
       | NoZebra120vClip wrote:
       | This would make the perfect TBBT episode title.
        
       | hannob wrote:
       | Given these DNS poisoning attacks come up every now and then, I
       | have a question, and maybe someone here can answer: My
       | understanding is that this is purely an UDP problem. So... why
       | not just say we'll deprecate DNS over UDP at least for the
       | communication between the resolver and the authoritative server?
       | DNS over TCP is required since like forever (was it ever not
       | required?), so it shouldn't be a problem.
       | 
       | I doubt there's a performance problem either. UDP is probably a
       | bit faster, but resolver-authoritative communication shouldn't be
       | that much as things can be cached.
        
         | pipe_connector wrote:
         | Not everyone agrees that TCP support is required for DNS:
         | https://twitter.com/RichFelker/status/994667677112156161
         | 
         | Though I don't personally agree with that reading of the RFC.
        
       ___________________________________________________________________
       (page generated 2023-03-11 23:02 UTC)