TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Securing DNS's 'Last Mile'

1 点作者 smountcastle超过 14 年前

1 comment

smountcastle超过 14 年前
In the year since that blog post, does anyone know of any OS vendors whose stub resolvers support TSIG? The key distribution issue is a barrier, but I would think that recursive DNS providers (like OpenDNS, Google, and others) would be interested in differentiating their services by providing this additional layer of protection.<p>One solution is to run a forwarding server on the customer's computer and use TSIG to secure its communication with the recursive service, but this won't work for every device in the household. I can't run a forwarding DNS server on my iPad and I wouldn't want all of the devices in my house to have to funnel their DNS through a single computer which could be off and break DNS.<p>Any ideas on how to solve this problem?