[HN Gopher] The CoreDNS Cache Poisoning Conjecture
___________________________________________________________________
The CoreDNS Cache Poisoning Conjecture
Author : sbudella
Score : 50 points
Date : 2023-03-09 13:23 UTC (2 days ago)
(HTM) web link (sbudella.altervista.org)
(TXT) w3m dump (sbudella.altervista.org)
| NoZebra120vClip wrote:
| This would make the perfect TBBT episode title.
| hannob wrote:
| Given these DNS poisoning attacks come up every now and then, I
| have a question, and maybe someone here can answer: My
| understanding is that this is purely an UDP problem. So... why
| not just say we'll deprecate DNS over UDP at least for the
| communication between the resolver and the authoritative server?
| DNS over TCP is required since like forever (was it ever not
| required?), so it shouldn't be a problem.
|
| I doubt there's a performance problem either. UDP is probably a
| bit faster, but resolver-authoritative communication shouldn't be
| that much as things can be cached.
| pipe_connector wrote:
| Not everyone agrees that TCP support is required for DNS:
| https://twitter.com/RichFelker/status/994667677112156161
|
| Though I don't personally agree with that reading of the RFC.
___________________________________________________________________
(page generated 2023-03-11 23:02 UTC)