Paul Vixie Responds To DNS Hole Skeptics 147
syncro writes "The recent massive, multi-vendor DNS patch advisory related to DNS cache poisoning vulnerability, discovered by Dan Kaminsky, has made headline news. However, the secretive preparation prior to the July 8th announcement and hype around a promised full disclosure of the flaw by Dan on August 7 at the Black Hat conference has generated a fair amount of backlash and skepticism among hackers and the security research community. In a post on CircleID, Paul Vixie offers his usual straightforward response to these allegations. The conclusion: 'Please do the following. First, take the advisory seriously — we're not just a bunch of n00b alarmists, if we tell you your DNS house is on fire, and we hand you a fire hose, take it. Second, take Secure DNS seriously, even though there are intractable problems in its business and governance model — deploy it locally and push on your vendors for the tools and services you need. Third, stop complaining, we've all got a lot of work to do by August 7 and it's a little silly to spend any time arguing when we need to be patching.'"
I'm not worried (Score:5, Funny)
Re:I'm not worried (Score:5, Funny)
Why is that hard? Still works with IP-addresses. The only thing you need to do is to supply the Host-field as per HTTP/1.1.
Re:The back-biting is shameful (Score:5, Funny)
If there's one thing that everyone should have learned by now, if someone says "trust me", you should be skeptical.
No, you're off message. They need to click continue, because the screen has gone all dark and they can't get back to their web browser.
Re:I'm not worried (Score:5, Funny)
I just remember the IP addresses and type them in myself. How hard is that?
That's all well and dandy until banner ads start flashing subliminal messages of unauthorized zone updates to you.
Re:I'm not worried (Score:4, Funny)
Re:I'm not worried (Score:2, Funny)
Re:stability (Score:2, Funny)
I heard that this "security fix" is the addition of support for the Evil Bit [faqs.org].
Re:Unfortunately, what else is new? (Score:5, Funny)
Your mad ad hominem attack skills have convinced everyone that Paul Vixie is the know nothing douchebag in this conversation. Kudos!
Re:I'm not worried (Score:5, Funny)
Hey!
I am an unpatched DNS server, you insensitive clod!
Re:Unfortunately, what else is new? (Score:4, Funny)
Re:I'm not worried (Score:5, Funny)
That's why 'smart' people use /etc/hosts. That solves the problem of remembering and of the HTTP-host-header.
It's all a liberal plot (Score:5, Funny)
DNS cache poisoning is a myth cooked up by the liberal media and DNS scientists to implement their anti capitalist agenda.
And if it isn't a myth, then it certainly isn't man made, it's a natural phenomenon and there's nothing we can do about it.
Re:ATTENTION MODERATORS: MOD PARENT DOWN (Score:4, Funny)
Uh oh, somebody call the whaaaaambulance, we're going to need to perform a humor transplant here!
Re:ATTENTION MODERATORS: MOD PARENT DOWN (Score:4, Funny)
User ID 1352 trollin' it old skool!
Re:Not so simple. (Score:3, Funny)
Only if you have a method for authenticating the other side of the phone conversation.
Visit the website and get the phone number, of course!
Don't worry, Mr. Vixie (Score:3, Funny)
Third, stop complaining, we've all got a lot of work to do by August 7 and it's a little silly to spend any time arguing when we need to be patching.
The patch is now in my crontab and set to run on the 6th.