5 ms·
Looks like you need to make a DNS request to a malicious server to be vulnerable. This means you are safe if you are using 8.8.8.8? Or another trusted network?
by TotallyGod 9y ago
Looks like you need to make a DNS request to a malicious server to be vulnerable. This means you are safe if you are using 8.8.8.8? Or another trusted network? (Or your ISP if you trust they haven't been compromised).
- qb45 9y agoThe real danger is a script kiddie on your LAN with a sniffer or some advanced attacker in the position to MITM you on the wide Internet, depending on whether you are a small fish or a big fish.
- 5ilv3r 9y agoUS corporations control the root name servers and seem to have no problem cooperating with government requests to fuck^H^H^H^Hkeep a close eye on everyone else.
- pas 9y agoK root is operated by RIPE NCC M root is opreated by WIDE from Japan http://root-servers.org/ http://root-servers.org/ Use DNSSEC, it's pretty tamper proof, keys are in HSM and "geo distributed" ( https://www.schneier.com/blog/archives/2010/07/dnssec_root_key.html https://www.schneier.com/blog/archives/2010/07/dnssec_root_k... ), the weak points are probably the facilities themselves in the US (one on the East Coast and one on the West Coast), but the trust anchor is pretty much fixed in the root servers, and it'd be quickly discovered if someone rolled a new one out of schedule.
- tptacek 9y agoDNSSEC does absolutely nothing to resolve the problem the parent commenter is referring to. In fact, DNSSEC cryptographically ratifies the status quo of the most important TLDs being de-facto controlled by Five Eyes governments. In years of watching for mentions of DNSSEC on HN, I can't remember off the top of my head a single case in which DNSSEC was introduced into a conversation as having some benefit where that benefit was real. It's weird what people believe about DNSSEC.
- pas 9y agoPlease elaborate. Parent seems worried about the root servers serving malicious responses for any given domain. (While assuming all root servers are under US control.) In case of a non-US controlled TLD (.ru, .cn, .de, .eu) why DNSSEC is worthless?