3 ms·
> stuff such as the vulnerabilities in the DNS resolver because they reimplemented things from scratch without the necessary domain knowledge on how to do that
by someone12345 9y ago
> stuff such as the vulnerabilities in the DNS resolver because they reimplemented things from scratch without the necessary domain knowledge on how to do that securely that has been collected and implemented by the dozens of existing implementations over the decades
By domain knowledge how to do this securely in implementations tested oer time, do you mean something like https://access.redhat.com/articles/2161461 https://access.redhat.com/articles/2161461?
It doesn't look like systemd's resolver fares worse in comparison... In addition it can be sandboxed (and is), an advantage over having a resolver part of libc.
- zAy0LfpBZLC8mAC 9y agoThank you for the demonstration, that is indeed roughly what that lack of domain knowledge combined with arrogance looks like. Would you mind explaining how exactly sandboxing prevents cache poisoning?