Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[discussion] Answers must copy exact letter case from QuErY (0x20) #83

Open
pspacek opened this issue Apr 29, 2019 · 1 comment
Open
Labels
next Idea for the next DNS flag day - please discuss!

Comments

@pspacek
Copy link
Contributor

pspacek commented Apr 29, 2019

Specification: https://tools.ietf.org/html/draft-vixie-dnsext-dns0x20-00

Expected advantage: Little bit safer DNS queries, entropy added to queries makes it harder for attackers to spoof DNS answers.

Expected disadvantage: None

Expected implementation complexity for software developers: Negligible

Expected non-compliance: Small, major open-source DNS implementations already preserve query letter case correctly.

Research to confirm assumptions: TBD

@pspacek pspacek added the next Idea for the next DNS flag day - please discuss! label Apr 29, 2019
@vttale
Copy link

vttale commented May 12, 2019

While I'd like to see 0x20, I question whether it really has much value. While it is one more source of anti-spoofing entropy we could use, we already don't really have much of a problem with spoofing as it is, and spoofing is better defended against with DNSSEC anyway.

Maybe roll it into "let's have a flag day for multiple issues at once", but I wouldn't bother pursuing it standalone.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
next Idea for the next DNS flag day - please discuss!
Projects
None yet
Development

No branches or pull requests

2 participants