Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] Attack Countermeasures: An Exercise of Paranoia

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] Attack Countermeasures: An Exercise of Paranoia


Chronological Thread 
  • From: Alex <coyo AT darkdna.net>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] Attack Countermeasures: An Exercise of Paranoia
  • Date: Wed, 02 May 2012 16:52:05 -0500
  • Openpgp: id=C34ED745

On 5/2/2012 4:03 AM, webmaster AT blockaid.me wrote:
> I realise I am new here, but I have to agree with Falk.

Falker seems fairly proficient in name servers, which is exactly what I
expected from a mailing list about name servers. So I don't disagree
with him, I was just disappointed by his tone.

> That being said, there is nothing wrong with implementing simple security
> measures on Opennic servers. I am talking about having strong ssh passwords
> and limited access to root etc. These kind of measures are probably already
> in
> place.
>
> With regard to DDOS, unless you use a host that specifically has protection,
> it is rather hard to mitigate an attack, whatever you do. I think its a case
> of crossing that bridge, if and when we come to it. Although choice of DNS
> software does help. Most of the servers here probably use bind and although
> its fast and reliable, there are far better alternatives, some of which have
> in-built DDOS protection. We use powerdns over at BlockAid.
>
> Anyway, just my two cents.

powerdns seems interesting, I'll have to take a look at it.

Thank you for the implicit suggestion.

Attachment: 0xC34ED745.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19.

Top of Page