Yadifa, new name server by .eu
yadifa.eu
yadifa.eu
1. a bunch of netsec/security geeks have looked at it (calling @tptacek, @cpercival)
2. @djb et al have ranted about it a bit. :)
till then it's going to be hard to imagine that they can get any traction with such crucial infrastructure.
Agreed - but it seems that this is an authoritative-only name server, which means it shouldn't be susceptible to cache poisoning, which is where the most awful DNS server security vulnerabilities have been.
Now that we have them, couldn't some core code be shared between all these projects and receive more scrutiny than it receives now? For example the code that parses incoming packets or generates replies could easily be shared (in theory).
Agreed that code sharing would be nice, and more important than ever since the rise of small servers with specific focus.
There are also advantages to having independent implementations for such crucial software. A fatal flaw that no one caught in one implementation may not take out the whole system.
Smaller problems require a lot of time, attention and testing to be found. To have a single code base can do wonder for this kind of smaller, but often fatal, problems.
dnscache for example doesn't (at least in my testing) connect over IPv6 to a remote name server to resolve a domain, nor does it do DNSSEC validation (and I understand DJB doesn't like DNSSEC, unfortunately it is here and I think that more and more having a validating resolver is a good idea).
The cool thing is that you can hook into the resolving chain with C and/or python.