Re: [dns-operations] MaginotDNS: Attacking the boundary of DNS caching protection

2023-09-26 Thread Xiang Li
Hi Stephane, This is Xiang, the author of this paper. For the off-path attack, DoT can protect the CDNS from being poisoned. For the on-path attack, since the forwarding query is sent to the attacker's server, only DNSSEC can mitigate the MaginotDNS. Best, Xiang On Tue, Sep 26, 2023 at 11:42 

[dns-operations] MaginotDNS: Attacking the boundary of DNS caching protection

2023-09-26 Thread Stephane Bortzmeyer
I'm reading the paper behind "MaginotDNS: Attacking the boundary of DNS caching protection" . Am I correct to think that forwarding