Gentoo Archives: gentoo-user

From: Michael Mol <mikemol@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] How to prevent a dns amplification attack
Date: Thu, 28 Mar 2013 21:00:22
Message-Id: 5154AF42.6020508@gmail.com
In Reply to: Re: [gentoo-user] How to prevent a dns amplification attack by Paul Hartman
1 On 03/28/2013 04:53 PM, Paul Hartman wrote:
2 > On Thu, Mar 28, 2013 at 3:02 PM, Alan McKinnon <alan.mckinnon@×××××.com> wrote:
3 >>>> Or just use the ISP's DNS caches. In the vast majority of cases, the ISP
4 >>>> knows how to do it right and the user does not.
5 >>>
6 >>> Generally true, though I've known people to choose not to use ISP caches
7 >>> owing to the ISP's implementation of things like '*' records, ISPs
8 >>> applying safety filters against some hostnames, and concerns about the
9 >>> persistence of ISP request logs.
10 >>
11 >> I get a few of those too every now and again. I know for sure in my case
12 >> their fears are unfounded, but can't prove it. Those few (and they are
13 >> few) can go ahead and deploy their own cache. I can't stop them, they
14 >> are free to do it, they are also free to ignore my advice of they choose.
15 >
16 > In my case, my ISP's DNS servers are slow (several seconds to reply),
17 > fail randomly when they should resolve, return an IP (which goes to
18 > their ad-laden "helper" website if you are using a web browser) when
19 > they should instead return nxdomain, and they have openly admitted to
20 > selling customer DNS lookup history to marketers for targeted
21 > advertising.
22
23 Wow. That's...all the fail.
24
25 >
26 > Thanks for being one of the good guys. :)
27 >
28
29 Indeed.

Attachments

File name MIME type
signature.asc application/pgp-signature