Edward Lewis <ed.le...@neustar.biz> wrote:

> We've collectively known about Dan Bernstein's use of t=ANY for a decade
> and we know he's reluctant to listen to calls for change nor make the
> change.

It's a bit unfair to blame DJB for bugs in software he abandoned 14 years
ago and which is now maintained by other people. In any case bugs in qmail
are irrelevant to the problem of DDOS attacks.

> PS - One possibility, instead of simply not responding, send back
> rcode=REFUSED.

Minimum-size truncated packets are the same size and friendlier to the
victim of the attack. See the RRL "slip" feature.

Tony.
-- 
f.anthony.n.finch  <d...@dotat.at>  http://dotat.at/
Viking: North 5 to 7. Rough, occasionally moderate later. Mainly fair. Good.
_______________________________________________
dns-operations mailing list
dns-operations@lists.dns-oarc.net
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to