Slashdot Mirror


Paul Vixie Responds To DNS Hole Skeptics

syncro writes "The recent massive, multi-vendor DNS patch advisory related to DNS cache poisoning vulnerability, discovered by Dan Kaminsky, has made headline news. However, the secretive preparation prior to the July 8th announcement and hype around a promised full disclosure of the flaw by Dan on August 7 at the Black Hat conference has generated a fair amount of backlash and skepticism among hackers and the security research community. In a post on CircleID, Paul Vixie offers his usual straightforward response to these allegations. The conclusion: 'Please do the following. First, take the advisory seriously — we're not just a bunch of n00b alarmists, if we tell you your DNS house is on fire, and we hand you a fire hose, take it. Second, take Secure DNS seriously, even though there are intractable problems in its business and governance model — deploy it locally and push on your vendors for the tools and services you need. Third, stop complaining, we've all got a lot of work to do by August 7 and it's a little silly to spend any time arguing when we need to be patching.'"

16 of 147 comments (clear)

  1. I'm not worried by niceone · · Score: 5, Funny

    I just remember the IP addresses and type them in myself. How hard is that?

    1. Re:I'm not worried by Klaus_1250 · · Score: 5, Funny

      Why is that hard? Still works with IP-addresses. The only thing you need to do is to supply the Host-field as per HTTP/1.1.

      --
      It only takes one man to change the Wisdom of the Crowd to Tyranny of the Masses.
    2. Re:I'm not worried by cnettel · · Score: 4, Funny

      I just remember the IP addresses and type them in myself. How hard is that?

      That's all well and dandy until banner ads start flashing subliminal messages of unauthorized zone updates to you.

    3. Re:I'm not worried by Toutatis · · Score: 4, Funny

      How can you know then that the flaw isn't in your mind too.

    4. Re:I'm not worried by morgauo · · Score: 2, Funny

      Meh! Just put the domains in your hostfile.... All of them....

    5. Re:I'm not worried by Nullav · · Score: 5, Funny

      Hey!
      I am an unpatched DNS server, you insensitive clod!

      --
      I just read Slashdot for the articles.
    6. Re:I'm not worried by Lennie · · Score: 4, Funny

      That's why 'smart' people use /etc/hosts. That solves the problem of remembering and of the HTTP-host-header.

      --
      New things are always on the horizon
  2. Re:The back-biting is shameful by wild_quinine · · Score: 4, Funny

    If there's one thing that everyone should have learned by now, if someone says "trust me", you should be skeptical.

    No, you're off message. They need to click continue, because the screen has gone all dark and they can't get back to their web browser.

  3. Re:stability by hostyle · · Score: 2, Funny

    I heard that this "security fix" is the addition of support for the Evil Bit.

    --
    Caesar si viveret, ad remum dareris.
  4. Re:Unfortunately, what else is new? by danFL-NERaves · · Score: 5, Funny

    Your mad ad hominem attack skills have convinced everyone that Paul Vixie is the know nothing douchebag in this conversation. Kudos!

  5. Re:Unfortunately, what else is new? by MadMidnightBomber · · Score: 3, Funny

    You broke my sarcasm meter.

    --
    "It doesn't cost enough, and it makes too much sense."
  6. It's all a liberal plot by spun · · Score: 4, Funny

    DNS cache poisoning is a myth cooked up by the liberal media and DNS scientists to implement their anti capitalist agenda.

    And if it isn't a myth, then it certainly isn't man made, it's a natural phenomenon and there's nothing we can do about it.

    --
    - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
  7. Re:ATTENTION MODERATORS: MOD PARENT DOWN by spun · · Score: 3, Funny

    Uh oh, somebody call the whaaaaambulance, we're going to need to perform a humor transplant here!

    --
    - None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
  8. Re:ATTENTION MODERATORS: MOD PARENT DOWN by Goaway · · Score: 3, Funny

    User ID 1352 trollin' it old skool!

  9. Re:Not so simple. by skarphace · · Score: 2, Funny

    Only if you have a method for authenticating the other side of the phone conversation.

    Visit the website and get the phone number, of course!

    --
    Bullish Machine Tzar
  10. Don't worry, Mr. Vixie by 93+Escort+Wagon · · Score: 2, Funny

    Third, stop complaining, we've all got a lot of work to do by August 7 and it's a little silly to spend any time arguing when we need to be patching.

    The patch is now in my crontab and set to run on the 6th.

    --
    #DeleteChrome