nanog mailing list archives

Re: DNS Hijacking by Cox


From: Chris Adams <cmadams () hiwaay net>
Date: Mon, 23 Jul 2007 08:56:34 -0500


Once upon a time, Steven M. Bellovin <smb () cs columbia edu> said:
Several people have email me privately to disagree with my statement
about DNSSEC, on various grounds.  I stand by my statement, but I am
making a fair number of assumptions, some perhaps invalid.  Let me be
less terse.

Okay, so instead of changing the DNS record, they snoop it and redirect
the IPs.  What have you gained?  How many IRC servers (especially those
used by the botnets) use SSL, and how many clients validate the cert?
-- 
Chris Adams <cmadams () hiwaay net>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.


Current thread: