[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [DNSOP] I-D Action:draft-ietf-dnsop-reflectors-are-evil-06.txt
In message <231A040F-13C4-4CC0-B202-D93A7E1A1445 at virtualized.org>, David Conrad
writes:
> [cc's cleaned up]
>
> Hi,
>
> > At his point, I will sit quietly for a while and let the WG comment
> > on whether they think that your proposed
> > alternative mitigation is adequate. On Friday, the WG chairs will
> > gauge consensus and I will take appropriate action.
>
> Given the stunningly successful implementation of BCP038 over the 8
> years since it has been published, I believe relying on it as a
> mitigation strategy against open resolver attacks is simply silly and
> discussing it largely a waste of time.
While I encourage everyone to deploy BCP 38, wherever possible, I
don't believe we should be relying on BCP 38 deployment to prevent
recursive servers being abused.
Mark
--
Mark Andrews, ISC
1 Seymour St., Dundas Valley, NSW 2117, Australia
PHONE: +61 2 9871 4742 INTERNET: Mark_Andrews at isc.org
_______________________________________________
DNSOP mailing list
DNSOP at ietf.org
https://www.ietf.org/mailman/listinfo/dnsop