4 ms·
DNS Monitoring is a mandatory security requirement for anyone serious about DNS Security today. https://dnsspy.io https://dnsspy.io is a good example of this.
by Bucephalus355 8y ago
DNS Monitoring is a mandatory security requirement for anyone serious about DNS Security today. https://dnsspy.io https://dnsspy.io is a good example of this.
Also, although I don’t think there is 100% agreement on this in the community, use LONG ttl’s. No reason to make yourself vulnerable by constantly reaching out to DNS every 5 minutes. Also makes you more likely to pick up a spoofing / hijacking attempt.
NOTE: also quick shout out to GCP here. I make all my money within AWS so if anything should not be saying this but there DNS security is amazing. They have DNSSEC + the crazy obscure records like IPSECKEY and TLSA and SSHFP. Wow.
- viraptor 8y ago> use LONG ttl’s It really depends on what you want to achieve. Australian census for example shot themselves in the foot by publishing relatively long ttl and not being able to migrate away from a failing system fast enough.
- Bucephalus355 8y agoAcknowledged and this is a really good point. Currently I’m straddling the fence on this one and doing a 2 hour DNS Record time. Also want to mention GEOIP blocking. I hate it’s come to this for the interment, but for a lot of sites, especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site. Again this is debatable advice but worth considering. All of the major cloud providers have GeoIP Blocking or are rolling it out.
- zulln 8y agoWhat do you aim to achieve with geoblocking?
- nicolaslem 8y agoIn real life geoip blocking is terrible. IPs are traded from one organization to another all the time. It often takes months for services to update their databases mapping IPs to locations. What is a user supposed to do when a random website blocks him because it uses an outdated database?
- viraptor 8y agoThis also impacts law enforced limits. What do you do when you're a Polish user under an ISP sharing a block of IPs with Ukrainian part of that company, which is now blocked because of being geolocated in Crimea.
- viraptor 8y ago> especially small businesses and local/state gov, there is very little reason someone outside the country or say outside the EU / bordering countries might need to access your site That is terribly shortsighted. I'm located long way away from many tiny shops I'm using for presents for friends and family. Local gov's published development plans are likely interesting to foreign investors. There are many other cases surely...