North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: how to protect name servers against cache corruption

  • From: Randy Bush
  • Date: Tue Jul 29 23:33:39 1997

> this statement bothers me.  certainly without DNSSEC there can be no 
> *assurances* of security,

While there are often assurances of security, there can never be assurance
of security.

> there is a gaping chasm between the current system and DNSSEC that could
> be closed significantly with proper design.
>
> simply stating that until DNSSEC arrives these attacks are going to be 
> allowed is a copout.

Send code.

randy