PING

DNS spoofing is a non-issue if we all do DNSSEC


Listen Later

APNIC's Chief Scientist, Geoff Huston joins us again on the show, this time to discuss three related presentations by Google, ISC and Mozilla that caught his attention during the recent IETF 114 and DNS-OARC 38 meetings on securing the DNS against spoofing.


DNS spoofing involves third parties intercepting and responding to queries for benign or malicious purposes; recent studies show that DNS spoofing has more doubled since 2016.


Google is protecting its DNS service against spoofing using multiple methods including using a combination of DNS cookies, randomizing the choice of name servers, stripping duplicate queries from the outbound queues, performing rate limiting and unilaterally probing for support of Authoritative DNS over TLS (ADoT); it projects that these measures will cover 99% of queries after the various rollouts are complete.


While such results are impressive, Geoff and others argue that the widespread use of DNSSEC could do just as good as a job and with little impact on performance, as per ISC's and Mozilla's findings in their recent studies.


Read more about DNS Spoofing and DNSSEC on the APNIC Blog:

  • Geoff's Notes from DNS-OARC 38 and IETF 114 for more detail on and links to these presentations.
  • Whac-A-Mole: Six years of DNS spoofing
  • Spoofing packets: What is it, and why do people do it?
  • DNSSEC: The long and bumpy road of algorithm deployment


The views expressed by the featured speakers are their own and do not necessarily reflect the views of APNIC.

...more
View all episodesView all episodes
Download on the App Store

PINGBy APNIC

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like PING

View all
This American Life by This American Life

This American Life

90,932 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

290 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

The Everything Feed - All Packet Pushers Pods by Packet Pushers

The Everything Feed - All Packet Pushers Pods

195 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

268 Listeners

Risky Business by Patrick Gray

Risky Business

372 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

Python Bytes by Michael Kennedy and Brian Okken

Python Bytes

215 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,057 Listeners

The Hedge by Russ White

The Hedge

16 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

N Is For Networking by Packet Pushers

N Is For Networking

21 Listeners