have you heard the man? Maybe he's serious on his job and want extra security. You can query DNS directly with dig or other tool, directly the root servers of most common accessed sites and put it on alias file. So it wouldn't be necessary to install bind except for seeing the addresses initially (diging localhost) and then uninstalling it. You can even config dns to localhost or another invalid dns configured on connection, that's what I meant, if that's the case. I don't know internals of iCAN, but perhaps you're right. But I remind you that neutrality is for adults only, ok? perhaps you need to learn some netiquette, because Caps seams like shouting things... You worry about dns hijacking, but some people worry about wrong advice on opensource forums, like providing wrong DNS numbers on forums (which I haven't checked if that's the case). Some people also worry a lot on DNS poisoning, specially on a Windows system. Windows system queries the dns server and retains info for a longgggg time, so if someone hacks the dns or tricks user to use a different dns, that can't be immediately fixed, and damage is a big one, these could lead to even large zombie networks, if it is an organized attack. But perhaps you're right about controlling freak part, perhaps they should be more flexible and avoid power abuse, if that's the case (I don't know how does it act, but once I red a good description from them).

Reply via email to