[145275] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: F.ROOT-SERVERS.NET moved to Beijing?

daemon@ATHENA.MIT.EDU (Danny McPherson)
Mon Oct 3 09:30:07 2011

From: Danny McPherson <danny@tcb.net>
In-Reply-To: <alpine.LSU.2.00.1110031227350.30178@hermes-2.csi.cam.ac.uk>
Date: Mon, 3 Oct 2011 09:27:46 -0400
To: NANOG list <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Oct 3, 2011, at 7:29 AM, Tony Finch wrote:
> 
> If you are running BIND 9.8 there is really no reason not to turn on
> DNSSEC validation, then you won't have to worry about anycast routes
> leaking from behind the great firewall.

User Exercise:  What happens when you enable integrity checking in an 
application (e.g., 'dnssec-validation auto') and datapath manipulation 
persists?  Bonus points for analysis of implementation and deployment 
behaviors and resulting systemic effects.

Network layer integrity techniques and secure routing infrastructure are 
all that's going to fix this.  In the interim, the ability to detect such 
incidents at some rate faster than the speed of mailing lists would be
ideal.

-danny


home help back first fref pref prev next nref lref last post