Re: OpenDNS today announced it has adopted DNSCurve to secure DNS

2010-03-07 Thread Danny Mayer
Michael Sinatra wrote: > On 02/24/10 01:25, Jonathan de Boyne Pollard wrote: >>> >>> >>> DNScurve advocates, on the other hand, point out that DNS isn't >>> encrypted. Well, neither is the phone book. So what? >>> >> So the protocol is vulnerable to both local and remote forgery attacks, >> just li

Re: SERVFAIL for some domains on some servers

2010-03-07 Thread Florian Weimer
* Kevin Darcy: > I'm not sure those recommendations apply as strongly as they used > to. Now we have views and (if the original poster were to upgrade to > 9.4.x or higher) fine-grained control over access to cached data. Views are probably okay. Access control is insufficient, especially if you