Hacker News new | past | comments | ask | show | jobs | submit login
Securing DNS's 'Last Mile' (cricketondns.com)
1 point by smountcastle on Jan 28, 2011 | hide | past | favorite | 1 comment



In the year since that blog post, does anyone know of any OS vendors whose stub resolvers support TSIG? The key distribution issue is a barrier, but I would think that recursive DNS providers (like OpenDNS, Google, and others) would be interested in differentiating their services by providing this additional layer of protection.

One solution is to run a forwarding server on the customer's computer and use TSIG to secure its communication with the recursive service, but this won't work for every device in the household. I can't run a forwarding DNS server on my iPad and I wouldn't want all of the devices in my house to have to funnel their DNS through a single computer which could be off and break DNS.

Any ideas on how to solve this problem?




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: