Re: [dns-operations] on fragmentation attacks; see also RFC 6013

2013-09-13 Thread Jared Mauch
On Sep 13, 2013, at 5:58 PM, Paul Vixie wrote: >> Although i think it is valid to argue that DNS TCP requires 3x RTTs if >> you want to count the original question over UDP + the TC=1 response. >> But I don't think that's what you are saying in the article. Am I >> interpreting it wrong? > > i

Re: [dns-operations] on fragmentation attacks; see also RFC 6013

2013-09-13 Thread Paul Vixie
Colm MacCárthaigh wrote: > > You write that it takes 3x RTTs to exchange a question and an answer > over TCP. I think it takes 2x RTTs, simple as that. FIN plays no role > in answer termination; clients don't wait on a FIN to decide that an > answer is usable. in this article i could not go into