Live data from Hacker News

DNS Firewalling with MISP and Technitium DNS Server

zaferbalkan.com

21–23 of 23 posts

Re: DNS Firewalling with MISP and Technitium DNS Server

#21
post #10
post #4

Don't get too exited - Technitium has a bus factor of one, a very small user base and no previous auditing.

Yea, I often wonder when I see this type of article, why don't they just use bind9? No other DNS resolver is going to come close to it's number of deployment*years in operation. I didn't read the article though, since I'm not going to enable javasript and cookies just to read someone's blag post 8-/ HTML much?

> I didn't read the article though, since I'm not going to enable javasript and cookies just to read someone's blag post 8-/

mirror: https://archive.vn/8BCBn

Re: DNS Firewalling with MISP and Technitium DNS Server

#22
post #16

Earlier quoted context omitted.

I guess wikipedia doesn't agree with you: "BIND is the de facto standard DNS server" https://en.wikipedia.org/wiki/Comparison_of_DNS_server_softw... 9 just being the currently deployed version. A non-wikipedia reference: https://dn.org/a-comprehensive-comparison-of-popular-dns-ser... Although this article does state that bind's "configuration files and options require careful attention to detail". So, maybe it's not…

> I guess wikipedia doesn't agree with you: Are you kidding? Bind has been the de facto standard for DNS servers for ages but it's just a badly engineered piece of software and had braindead vulnerabilities for decades: https://www.cvedetails.com/vulnerability-list/vendor_id-64/p... Already 20 years ago it was common knowledge to never use software that Paul Vixie had touched (bind, vixie-cron, sendmail ...) and we u…

After just a short search to try to come up with some numbers, I find that between 60% and 90% of internet DNS servers are running bind.

And yet somehow, the internet has much bigger problems...

Re: DNS Firewalling with MISP and Technitium DNS Server

#23
post #22

Earlier quoted context omitted.

> I guess wikipedia doesn't agree with you: Are you kidding? Bind has been the de facto standard for DNS servers for ages but it's just a badly engineered piece of software and had braindead vulnerabilities for decades: https://www.cvedetails.com/vulnerability-list/vendor_id-64/p... Already 20 years ago it was common knowledge to never use software that Paul Vixie had touched (bind, vixie-cron, sendmail ...) and we u…

After just a short search to try to come up with some numbers, I find that between 60% and 90% of internet DNS servers are running bind. And yet somehow, the internet has much bigger problems...

Bold statement just one month after the last cache poisoning vulnerability. Bind is the Microsoft Windows of DNS servers - a lot of users and bugs nonetheless the go-to for many admins because that's what they are most familiar with. And similar to Windows, the internet mostly relies on others - none of the big companies (Meta, Cloudflare, Google, MS, Amazon, Netflix, Twitter...) use bind and neither do most hobbyists. It's just for the plethora of mid-sized companies with unmotivated admins.
Post reply on HN