> On Feb 29, 2024, at 07:52, Edward Lewis <edward.le...@icann.org> wrote:

>  (If no action is taken, malicious activity might follow now that it is 
> described, but I have not heard of a historical case of it.) 

This attack was more or less described five year ago: 
https://essay.utwente.nl/78777/

They didn’t get to the same amplification levels but if attackers had been 
interested, they could have picked it up as a tool to improve. scripts to run 
were attached to the paper.

But also, a resolver that sees a higher than normal load could temporarily take 
certain actions like sacrificing zones with key tag collisions. It doesn’t mean 
it ALWAYS has to do it.

Paul


_______________________________________________
DNSOP mailing list
DNSOP@ietf.org
https://www.ietf.org/mailman/listinfo/dnsop

Reply via email to