Hacker News new | past | comments | ask | show | jobs | submit login

Do you mean Dan kaminsky's issue from 2008? (https://en.wikipedia.org/wiki/Dan_Kaminsky#Flaw_in_DNS)

If so, this was fixed... in 2008.




Fixed is much too strong a word. Mitigated is more descriptive. From your link:

> This fix is widely seen as a stopgap measure, as it only makes the attack up to 65,536 times harder. An attacker willing to send billions of packets can still corrupt names.


Fair.


Nah, they'd be able to use a much more surgical approach because they wouldn't need to guess the txid. They can just spool off packets that match what they're looking for and respond to them themselves instead of sending them along to 8.8.8.8 or whoever.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: