Settings

Theme

Zone Dumping via DNSSEC

harrisonm.com

5 points by thricegr8 2 years ago · 3 comments

Reader

johnklos 2 years ago

This is neat. I didn't know about that shortcoming of DNSSEC, but knowing now, I'll definitely use NSEC3.

I've also naively taken it for granted that some of my machines that're only running ssh on IPv6 wouldn't be subject to brute force attacks, but now I can see how someone might discover DNS names that aren't shared publicly. Good to know!

  • tptacek 2 years ago

    NSEC3 is not much better! It's usually a simple iterated hash, of the sort Unices used in the 1990s before the invention of bcrypt, so they can cracked the same way a 1990s password file would be.

    • johnklos 2 years ago

      Yes, it's not much better, but it's better than nothing. It'll at least make people work a little.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection