-----Original Message-----
From: Mark Andrews <ma...@isc.org>
Date: Tuesday, April 14, 2015 at 3:57 PM
To: Edward Lewis <edward.le...@icann.org>
Cc: "dns-operati...@dns-oarc.net" <dns-operati...@dns-oarc.net>
Subject: Re: [dns-operations] Stunning security discovery: AXFR may
leak    information

>Basically all blocking axfr does is give you a false sense of
>security for typical zones.

Sort of like curtains on your windows, or car alarms...yet many have
those, arguably for good reason.  At the very least, you probably don't
want to be the only person on your block that doesn't.  You should of
course understand that those things alone do not provide complete
security, and have the choice to use them or not.

Alas, I think we are nitpicking personal preferences of knowledgeable
operators (of which there could be no end) vs the advisory...the latter of
which I think we all agree was kinda lame.  :-)


_______________________________________________
dns-operations mailing list
dns-operations@lists.dns-oarc.net
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to