ATTBI refuses to do reverse DNS?

Greg A. Woods woods at weird.com
Wed Jun 19 03:23:38 UTC 2002


[ On Tuesday, June 18, 2002 at 17:47:10 (-0400), Daniel Senie wrote: ]
> Subject: Re: ATTBI refuses to do reverse DNS?
>
> While I believe people SHOULD be providing INADDR service, the people hurt 
> by refusing connections are rarely the ones who have any influence.

On the contrary!

The people who are supposedly hurt here are those who ultimately have
the most influence.  In the end they can vote with their wallets even if
they can't edit the appropriate zone files directly.  (And the whole
idea behind DNS trust really revolves around having two different
parties agree on the mapping, not in simply allowing the user to edit
their own reverse DNS!) 

> Just as 
> Network Address Translation is not a security solution, neither is checking 
> INADDR.

I don't think anyone has said that DNS consistency is a security
solution.  You keep confusing these concepts I think.  It's only one
tiny part of the picture.  Fully consistent DNS only increases the level
of trust you can have in the hostnames used.  Since hostnames are
supposed to be more stable than IP addresses, you _want_ to have more
trust in the hostnames, but with current protocols you cannot unless
there is full consistency between forward and reverse lookups.

> Now if you check INADDR over Secure DNS, you might start having 
> some level of information to trust.

We can only hope, but I'll believe it when I see it.

-- 
								Greg A. Woods

+1 416 218-0098;  <gwoods at acm.org>;  <g.a.woods at ieee.org>;  <woods at robohack.ca>
Planix, Inc. <woods at planix.com>; VE3TCP; Secrets of the Weird <woods at weird.com>



More information about the NANOG mailing list