// 1.  plan 9 never used a static source port for queries,

Using dynamic ports is better than static, but if they're
sequential (or otherwise predictable), it doesn't buy you
all that much.

// 2.  who does recursive queries on external interfaces?

I've been traveling in companies and countries with
restricted local DNSs, but open routes to home. Or open
enough to get DNS through; sometimes not VPN, ssh, or
functional equivalent (to say nothing of 9p). Being able
to query an unrestricted DNS was wonderful.

I've also worked for companies who had folks working from
home pointing their home computers at work DNS (and some
other services) over the public internet. I'd probably
grant that it's a security problem, but it wasn't an
"error" in the normal sense.

Anthony

Reply via email to