[DNSOP] Re: [secdir] secdir review of draft-ietf-dnsop-reflectors-are-evil-04.txt (fwd)

2007-10-02 Thread Dean Anderson
I think this may be of interest. It was offlist, so I won't identify the author I am responding to. > [off-list] > > On Monday, September 24, 2007 06:25:49 PM -0400 Dean Anderson > <[EMAIL PROTECTED]> wrote: > > > > > I. Harm only possible for ENDSO; Update RFC 2671 Instead > > > > The max

Re: [DNSOP] Re: [secdir] secdir review of draft-ietf-dnsop-reflectors-are-evil-04.txt (fwd)

2007-10-02 Thread Brian Dickson
Dean Anderson wrote: I think this may be of interest. It was offlist, so I won't identify the author I am responding to. [Did you think to perhaps ask the author first? He/she may have been willing to be identified...] I. Harm only possible for ENDSO; Update RFC 2671 Instead The maximum no

Re: [DNSOP] Re: [secdir] secdir review of draft-ietf-dnsop-reflectors-are-evil-04.txt (fwd)

2007-10-02 Thread Dean Anderson
On Tue, 2 Oct 2007, Brian Dickson wrote: > Dean Anderson wrote: > > I think this may be of interest. It was offlist, so I won't identify > > the author I am responding to. > > > [Did you think to perhaps ask the author first? He/she may have been > willing to be identified...] The author is no

Re: [DNSOP] Re: [secdir] secdir review of draft-ietf-dnsop-reflectors-are-evil-04.txt (fwd)

2007-10-02 Thread John Kristoff
On Tue, 2 Oct 2007 21:59:33 -0400 (EDT) Dean Anderson <[EMAIL PROTECTED]> wrote: > In fact, using authority servers is _less_ risk to the abuser, because > to compose the reflector attacks, s/he has to crack into a server, > craft a record, One can create a large record anwhere in the namespace.

Re: [DNSOP] Re: [secdir] secdir review of draft-ietf-dnsop-reflectors-are-evil-04.txt (fwd)

2007-10-02 Thread Brian Dickson
Dean Anderson wrote: The load balancer is really just a special kind of stateful NAT. No. Load balancers can load balance, without any translation being done at all. And a load balancer is by definition doing *anycast*. The same address is used as a destination, and the packets are delivere