Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: DNS security
PostPosted: Wed Aug 24, 2011 1:40 am 
Offline
Newbie

Joined: Wed Aug 24, 2011 1:20 am
Posts: 2
If using DNS, how concerned should I be about DNS security issues such as cache poisoning and cache snooping?

According to Linode, "Our DNS platform is secure, especially when communicating over the private network."

I'm not sure how to assess how secure is "secure". The "especially" part of that sentence makes me wonder what aspect of it is less secure than optimally secure.

Using IP addresses is not a good alternative because the nature of the application would make it hard to migrate to new IP addresses at another hosting company if circumstances dictated a need to migrate.


Top
   
 Post subject:
PostPosted: Wed Aug 24, 2011 8:02 am 
Offline
Senior Member
User avatar

Joined: Sat Aug 30, 2008 1:55 pm
Posts: 1739
Location: Rochester, New York
If absolute assurance is required, deploying DNSSEC may be appropriate for your zones. That, along with DNSSEC-aware recursive nameservers, is the "best" way to ensure that recursive nameservers provide the correct answer.

For a more realistic answer :-), the first part of your question makes it sound like you're concerned about Linode's recursive nameservers (the ones in your resolv.conf), but the second part makes it sound like you're concerned about Linode's authoritative nameservers (the ones you point your domain at). The latter are, strictly speaking, not susceptible to cache attacks as they aren't recursive nameservers. The former, as with all other recursive nameservers, are at least a little bit susceptible. The situation used to be worse, but there have been improvements in recent years with how recursive nameserver software operates.

There is nothing you can do about your end users' recursive nameservers other than transitioning to DNSSEC and hope they've got secure connections to nameservers that support and validate DNSSEC. This is not common.

_________________
Code:
/* TODO: need to add signature to posts */


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group