Internet slows down after DNS attack on Spamhaus

Walter Dnes waltdnes-SLHPyeZ9y/tg9hUCZPvPmw at public.gmane.org
Fri Mar 29 18:30:11 UTC 2013


On Thu, Mar 28, 2013 at 10:39:25AM -0400, Lennart Sorensen wrote
> On Thu, Mar 28, 2013 at 08:59:37AM -0400, Thomas Milne wrote:
> > One curious line in this story says that the attack was partly enabled by
> > "open DNS", which it says are "known to be insecure".
> > 
> > Thoughts?
> > 
> > Internet slows down after DNS attack on Spamhaus
> > 
> > http://gu.com/p/3emqz
> 
> Plain old DNS is insecure.  This is part of why DNSSEC is being pushed,
> but not very many places are using it.

  Without egress filtering, will even DNSSEC stop these attacks?  Or are
we talking TCP 3-way handshakes for DNS?

-- 
Walter Dnes <waltdnes-SLHPyeZ9y/tg9hUCZPvPmw at public.gmane.org>
I don't run "desktop environments"; I run useful applications
--
The Toronto Linux Users Group.      Meetings: http://gtalug.org/
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists





More information about the Legacy mailing list