I see most of the bot traffic hiding behind Google and Cloudflare. I appreciate that. They take a lot of load off my servers. If I had one request of Google it would be to remove the TTL cap of 21600 or raise it to 86400 to further reduce the traffic that comes through from them as my TTL records are very high on purpose for my own reasons that I will not debate. I know memory is still a limit. CF seem to honor my TT…
A recursive resolver is not a database. They're under no obligation to cache for a day.
Google Public DNS's approach to fight against cache poisoning attacks
51–60 of 72 posts
Re: Google Public DNS's approach to fight against cache poisoning attacks
#52Re: Google Public DNS's approach to fight against cache poisoning attacks
#53Earlier quoted context omitted.
No, it obviously isn't, because less than 5% of zones are signed, and an even smaller fraction of important zones (the Moz 500, the Tranco list) are. That's why they don't mention DNSSEC: because it isn't a significant security mechanism for Internet DNS. It's also why they do mention ADoT: because it is. I think this is also why DNSSEC advocates are so fixated on DANE, which is (necessarily) an even harder lift than…
Many years ago, when HTTPS adoption was in the 5% range, if someone would have said “HTTPS is the ultimate defense against web page spoofing”, would you have argued that it was false, just because the adoption was so low? DNSSEC is the ultimate defense against cache poisoning attacks, no matter the adoption percentage.
Re: Google Public DNS's approach to fight against cache poisoning attacks
#54Earlier quoted context omitted.
The rabbit hole on people gradually pulling up stakes on DNSSEC goes deeper than that; I'd say the canary in the coal mine is probably Geoff Huston switching from "of course we're going to DNSSEC everything" to "are we going to DNSSEC anything?": https://www.potaroo.net/ispcol/2023-02/dnssec.html (Geoff Huston is an Internet infrastructure giant.) But really it all just boils down to the fact that the DNS zones that…
I urge everyone to actually read the blog post by Geoff Huston. From what I can tell, it does not say what tptacek says it does. Some other counterpoints to general DNSSEC doomsayers: • https://blog.technitium.com/2023/05/for-dnssec-and-why-dane-... > • https://www.redpill-linpro.com/techblog/2019/05/06/sshfp-and... >
Re: Google Public DNS's approach to fight against cache poisoning attacks
#55Earlier quoted context omitted.
Unfortunately it's quite easy for some actors to get a valid TLS cert https://notes.valdikss.org.ru/jabber.ru-mitm/
Quite astonishing that someone managed to get valid certs from Let's Encrypt for domains that they didn't own. Has Let's Encrypt issued any statements about how this might have happened, and how those specific certificates were validated by them? Still, good to see that monitoring the CT logs would have caught this problem much sooner.
Re: Google Public DNS's approach to fight against cache poisoning attacks
#56Earlier quoted context omitted.
I urge everyone to actually read the blog post by Geoff Huston. From what I can tell, it does not say what tptacek says it does. Some other counterpoints to general DNSSEC doomsayers: • https://blog.technitium.com/2023/05/for-dnssec-and-why-dane-... > • https://www.redpill-linpro.com/techblog/2019/05/06/sshfp-and... >
You keep citing these two random blog posts to me. I've never quite understood why you think they're such a mic drop. "Shreyas Zare, who develops software part-time as a hobby" thinks I'm all wrong. OK? Did Shreyas Zare connect Australia to the Internet before spending 15 years advocating for DNSSEC as the chief scientist at APNIC? I think my Pokemon wins here.
Edit: Is this authoritative enough for you? https://www.icann.org/resources/pages/dnssec-what-is-it-why-...>
Re: Google Public DNS's approach to fight against cache poisoning attacks
#57Earlier quoted context omitted.
Many years ago, when HTTPS adoption was in the 5% range, if someone would have said “HTTPS is the ultimate defense against web page spoofing”, would you have argued that it was false, just because the adoption was so low? DNSSEC is the ultimate defense against cache poisoning attacks, no matter the adoption percentage.
You should go tell Google that.
(I also note that you didn’t answer my question, and instead opted for a rhetorical cheap shot reply to my second paragraph only.)
Re: Google Public DNS's approach to fight against cache poisoning attacks
#58Earlier quoted context omitted.
You keep citing these two random blog posts to me. I've never quite understood why you think they're such a mic drop. "Shreyas Zare, who develops software part-time as a hobby" thinks I'm all wrong. OK? Did Shreyas Zare connect Australia to the Internet before spending 15 years advocating for DNSSEC as the chief scientist at APNIC? I think my Pokemon wins here.
I’m not citing them to you. I’m citing them to other readers here who do not have your attitude of dismissing arguments unless they’re made by someone in authority, in which case your proclaim them valid, and coincidentally supporting your viewpoint (even when they don’t; again, I urge readers to actually read Geoff Huston’s blog post for themselves). You’re literally making an argument from authority and making an a…
Re: Google Public DNS's approach to fight against cache poisoning attacks
#59Earlier quoted context omitted.
You should go tell Google that.
The needs and risk profiles of Google are vastly different than basically every other organization on Earth. (I also note that you didn’t answer my question, and instead opted for a rhetorical cheap shot reply to my second paragraph only.)
Re: Google Public DNS's approach to fight against cache poisoning attacks
#60Earlier quoted context omitted.
I’m not citing them to you. I’m citing them to other readers here who do not have your attitude of dismissing arguments unless they’re made by someone in authority, in which case your proclaim them valid, and coincidentally supporting your viewpoint (even when they don’t; again, I urge readers to actually read Geoff Huston’s blog post for themselves). You’re literally making an argument from authority and making an a…
I don't think we're playing the same game here. This is a random info page at ICANN from 2019. It doesn't even have a byline. I had to go to archive.org to figure out when it showed up. Why would you think this would be persuasive?