@orchid_hybrid @bascule (against. DNSSEC is actually not particularly terrible, compared to uh anything else that actually works)
@dakami @orchid_hybrid so it's slower, harder-to-deploy, poorly-authenticated DNS with amplification attacks that duplicates what X.509 does
-
-
@bascule @orchid_hybrid like for example, amplification comes from DNS, not DNSSEC, as evidenced by the enormous floods that aren't DNSSEC -
-
@jrmithdobbs@bascule @orchid_hybrid The solution to DNS amplification is not "maybe we should store less data in DNS" -
-
@jrmithdobbs@bascule @orchid_hybrid Huh? I'm the guy who put video in DNS :) And no, we're drowning in DNS floods *TODAY* w/o DNSSEC
End of conversation
New conversation -
-
-
@bascule @orchid_hybrid so much religionThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.