Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The amplification is by asking the misconfigured resolver about a DNSSEC zone.

Basically, DNSSEC just mean you do not need to search the for a large zone to request. Given that large zones are not directly in shot supply, and that searching for them is (in the age of ipv4) rather easy, I wonder if DNSSEC actually have any affect on the issue what so ever.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: