6 ms·
DNS based amplification has been very popular for many years now. By this point if a DNS resolver is still being used by amplification no email or contacting th
by CircleSpokes 5y ago
DNS based amplification has been very popular for many years now. By this point if a DNS resolver is still being used by amplification no email or contacting the ISP will do anything as they have received many other similar emails.
- flatiron 5y agoDns is so broken in many different ways. It’s crazy it’s still the back bone of the internet when it’s insecure awful nonsense. It’s just ingrained.
- worik 5y agoIt is not the back bone of the Internet. It is the back bone of most naming services. The internet is IP. It is very robust. DNS is an application over the top of the Internet.
- sroussey 5y agoThe public won’t be able to use the internet without it.
- Y_Y 5y agoThis is an interesting proposal. After some thought I must say I'm also in favour of it.
- wizzwizz4 5y agoThe public would still use internet applications, like Facebook. They just wouldn't be able to use the web any more.
- mitigating 5y agoApps use hostsnames 99% of the time.
- toast0 5y agoI don't think Facebook's apps work when there's no access to DNS. At least it didn't seem like it when I was working to keep that capability for WhatsApp as it moved into FB datacenters. I don't think very many other applications will work without DNS either, although I never did much competitive testing.
- xrisk 5y agoTelegram does AFAIK.
- wizzwizz4 5y agoFacebook could (relatively) easily modify their system to do its own IP handling; they probably have enough money to rebuild the entire stack.
- toast0 5y agoSure, they could, but at least while I was there, there was no interest in doing it, and amazement than anyone else would want to (and push back on declaring at least a handful of IPs as stably allocated enough to be included in app downloads).
- chx 5y agoWhen was the last time you read a URL aloud or typed it in?
- arthurcolle 5y agoa minute ago? what an outrageous question
- fiddlerwoaroof 5y agoI think many people Google “gmail” and click the link instead of memorizing URLs
- Firehawke 5y agoEven then you're going to be hitting up DNS to turn "www.gmail.com" into an IP address.
- edoceo 5y agoThen an HTTP redirect to mail.google.com
- teitoklien 5y agoAnd maybe to accounts.google.com too , if you’re not signed in
- oneplane 5y agoThe last 100 times were in the past few hours, roughly. Are you assuming nobody uses FQDNs or URLs anymore? Better yet, are you assuming only humans use those?
- freshpots 5y agoYou were both savage and self-deprecating, well done!
- zrm 5y agoModern UDP-based protocols handle this in two ways. First, prefer to make responses no larger than the request, so there is no amplification. Second, if the response has to be larger than the request, send the requestor an address-specific value in a small initial response, e.g. HMAC of a secret and the sender IP. Then any request that incurs a large response has to contain that value. If the sender is spoofing the IP address and can't receive the small response sent to that address, they can't cause a large response to be sent there. This can't be done with DNS because of "security" middleboxes. They ossify the protocol because they reject anything they don't understand, and they don't understand new versions of the protocol even if both of the endpoints do. So the protocol gets frozen in time and no security improvements can be made because of the things that claim to be there to improve security.
- anakaine 5y agoThat sounds like its time to push standards forward, announce deprecations in advance, and have as many end services as possible adopt erroring if what they are receiving isn't standards compliant. There is little actual reason for security middleware to not keep up.
- jfrunyon 5y agoExcept that in practice, deprecations don't work, no matter how much warning you give.
- anakaine 5y agoThe point of deprecations is to eventually force a bad experience for those who are not keeping up. They definitely do work, but the time periods to affect change can be long. In the tech sphere many seem to interpret a long transition period as not working granted the usual pace of change.
- NullPrefix 5y agoIs IPv4 deprecated already?