Skip to Content.
Sympa Menu

dns-operations - Re: [opennic-dns-operations ] updates from non-masters

dns-operations AT lists.opennicproject.org

Subject: Dns-operations mailing list

List archive

Re: [opennic-dns-operations ] updates from non-masters


Chronological Thread 
  • From: opennic AT lewman.us
  • To: dns-operations AT lists.opennicproject.org
  • Subject: Re: [opennic-dns-operations ] updates from non-masters
  • Date: Fri, 22 Jun 2012 20:52:22 -0400
  • Organization: The Tor Project, Inc.

On Fri, 22 Jun 2012 18:31:14 -0500
Brian Koontz <brian AT opennicproject.org> wrote:
> Dude, I'd worry more about auditing the security-riddled BIND code
> than worrying about security issues with Jeff's script. Your time
> would be better-spent.

If I ran bind8 sure. I run bind9 which has been fairly robust. It's run
in a chroot so at worst, someone breaks bind and then has to break the
chroot. Bypassing all of that with unknown text from the Internet seems
more risky than bind9.

If bind9 is so buggy, opennic should not rely on it for 100% of T1
servers and vast majority of T2 servers.

My server does not just run opennic, it runs some popular domains as
well, and slaves other popular domains.

It's also an open recursive resolver so people have options other than
the well-surveilled Level 3 dns server 4.1.1.1 and google dns servers,
8.8.8.8 and 8.8.2.2.

--
Andrew
pgp 0x6B4D6475



Archive powered by MHonArc 2.6.19.

Top of Page