A Deep Dive into DNS Packet Sizes
blog.cloudflare.com
blog.cloudflare.com
Forcing large payloads to upgrade to TCP responses is probably a more compatible fix for this in general.
There are other initiatives as well. But the problem is very difficult to solve.
It's entirely political/economic. There is no incentive for an ISP to do so because it provides no direct benefit. It's a classic issue of externalities.
While an explicit address could be designated for this, carriers would rather have control and surveillance voyeurs would have an easier target. It's better to not push to eliminate what end-to-end freedom we still have.
"Domains with DNSSEC, because of the size of some responses, are usually ripe for this type of abuse, and many DNS providers struggle to combat DNSSEC-based DDoS attacks. Just last month, Akamai published a report on attacks using DNS lookups against their DNSSEC-signed .gov domains to DDoS other domains. They say they have seen 400 of these attacks since November."
DDoS by DNS is something else entirely. The cookies that Bernstein advocate does not help here. Only ingress filtering helps, but it has to be implemented world wide before it useful, and not many bother unless forced to.
That much was well known at the time, and not something Bernstein predicted, but he has argued against adding yet another large record type to DNS. That's a good argument but at the same time not very helpful. The problem here is that there are several other queries with large replies and you just need one for an attack. Then there's all of NTP, and so on.
It's one of those problems likely to get worse before it gets better.
That's not how I read the linked essay. The lesson I get from that is that until relatively recently it was trivial to poison DNS responses requested by most DNS servers, and that it's still quite possible if you have a "nearby" malicious machine.
The CloudFlare essay appears to be talking about DDoS attacks via traffic amplification through large DNS queries.
Yes they both involve DNS, but -AIUI- nether DNSSEC nor DNSCurve will fix the problem mentioned in the CloudFlare essay.
Am I misunderstanding either essay?
ITYM: "To actually link to a talk where he talks about the topic I thought he was talking about..." ;)
But yeah, thanks for the links. That's good stuff.
Let's hope it is resistant to side-channel attacks[0] ;)
I wonder if removing side-channel countermeasures was part of the optimization?
So when the DO bit was set, the draft suggests returning unsigned records, because the initiator can then explicitly ask for HINFO and get a signed response.
However, resolvers just return SERVFAIL if the response doesn't validate. Will Qmail retry with more specific records after a SERVFAIL response code?