Re: [cryptography] [OT]: SQL injection blamed for widespread DNS hack

2011-09-11 Thread James A. Donald
It seems to me that if you use dynamic sql, you are bound to get injection attacks unless you are always careful, and you are not *always* going to be careful. So if you use dynamic sql, will always get injection attacks. If you use mysqli and stored procedures, and *never* use dynamic sql,

Re: [cryptography] [OT]: SQL injection blamed for widespread DNS hack

2011-09-11 Thread John Levine
>While PKI has many shortcomings, DigiNotar has shown the industry can >effectively kill off a deficient CA. Are there any measures in place >to keep a deficient registrar out of DNS? Or will NetNames still be >serving up records with a promise to do better? Interesting question. For registars fo

[cryptography] [OT]: SQL injection blamed for widespread DNS hack

2011-09-11 Thread Jeffrey Walton
While PKI has many shortcomings, DigiNotar has shown the industry can effectively kill off a deficient CA. Are there any measures in place to keep a deficient registrar out of DNS? Or will NetNames still be serving up records with a promise to do better? [Naively, I thought the DNS hacks were relat