[114558] in North American Network Operators' Group
Re: you're not interesting, was Re: another brick in the wall[ed
daemon@ATHENA.MIT.EDU (Andre Gironda)
Thu May 14 20:27:09 2009
In-Reply-To: <200905142358.n4ENwWPM094667@drugs.dv.isc.org>
Date: Thu, 14 May 2009 17:25:53 -0700
From: Andre Gironda <andre@operations.net>
To: "nanog@nanog.org" <nanog@nanog.org>
Cc: Mark Andrews <Mark_Andrews@isc.org>, rs@seastrom.com
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Thu, May 14, 2009 at 4:58 PM, Mark Andrews <Mark_Andrews@isc.org> wrote:
>> If I were an ISP, and I knew that approximately 99.9% of customer
>> queries to random name servers was malware doing fake site phishing or
>> misconfigured PCs that will work OK and avoid a support call if they
>> answer the DNS query, with 0.1% being old weenies like us, I'd do what
>> Sprint's doing, too.
>
> =A0 =A0 =A0 =A0And what's the next protocol that is going to be stomped o=
n?
I was going to say, "will the ISP also remove the DNS MITM the day
that 99.9% of malware moves its command-and-control to the HTTP or
other layer?". I figured why bother - but your point drives it home
even further.
dre