Tomas Mraz <tm...@redhat.com> writes:

> And if this malicious DNS administrator controls the caching
> nameserver you're using for DNS queries, he can present you ANY data
> even 'valid' fake DNSSEC data.

This is not generally true. Resolver libraries can (and should, IMHO)
verify DNSSEC themselves. Otherwise DNSSEC is somewhat pointless,
because it is precisely when you are stuck behind an untrusted Wifi
gateway that you need DNSSEC the most.


/Benny

-- 
devel mailing list
devel@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel

Reply via email to