On May 31, 2013, at 10:02 PM, Ken A wrote:

> What is keeping nameserver vendors from building this into servers?

Potentially severe scaling issues, plus it makes it a lot harder to 
detect/classify/mitigate DNS-based DDoS attacks if the traffic is encrypted.  
Fairly widespread misguided TCP/53 filtering, as well, if the DNSCrypt traffic 
is destined for TCP/53.

AFAIK, there's never been any real testing in the modern era of forcing all DNS 
queries via TCP (and not even back in Ye Olden Days; folks just assumed it 
wasn't scalable without any empirical evidence, AFAIK).  If it scales on modern 
hardware (as I personally think it might), DNS-over-TCP would solve a great 
deal of the problem-set DNSSEC is supposed to solve with far fewer moving 
parts, and all the way down to the stub resolver.  

And incidentally negating DNS reflection/amplification attacks as a beneficial 
side-effect.

-----------------------------------------------------------------------
Roland Dobbins <[email protected]> // <http://www.arbornetworks.com>

          Luck is the residue of opportunity and design.

                       -- John Milton

_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to