The hottest DNS Substack posts right now

And their main takeaways
Category
Top Technology Topics
Making It Up 39 implied HN points 27 Feb 23
  1. DNS management in AWS is now even easier with the release of AWS CDK Split Horizon DNS v0.0.9.
  2. You can import existing hosted zones into the SplitHorizonDns construct without recreating records.
  3. A new safeguard called `disallowPrivateZone` has been added to allow isolation of private zone resources.
Dataplane.org Newsletter 19 implied HN points 07 Feb 22
  1. Unsolicited DNS queries often don't pose a threat, with approximately 66% of queries being spoofed.
  2. IPv6 traffic is significantly lower than IPv4, making it less interesting to explore further.
  3. Dataplane.org is transitioning towards not-for-profit status and inviting members to a Slack workspace for communication.
Thái | Hacker | Kỹ sư tin tặc 0 implied HN points 26 Jul 08
  1. False negative results can be a risk if one DNS cache is patched but another is not, impacting the safety of clients.
  2. A NAT device can unintentionally protect vulnerabilities in DNS caches by causing randomization issues, affecting security tool results.
  3. Simple command line tools may offer more accurate DNS analysis results compared to potentially misleading specialized software, benefiting both regular users and sysadmins.
Thái | Hacker | Kỹ sư tin tặc 0 implied HN points 24 Jul 08
  1. Dan Kaminsky's research revealed DNS tricks like the 'CNiping' CNAME override, showing ways to manipulate cached data in DNS resolvers.
  2. Understanding the probability formula involving 'D', 'R', 'W', 'N', 'P', and 'I' can help in launching successful spoofing attacks on resolvers.
  3. Increasing 'R' and 'A' with specific values like 300 packets/s and 4000 queries can lead to a 51% success chance in poisoning target resolvers, showcasing the relative ease of the attack.
Thái | Hacker | Kỹ sư tin tặc 0 implied HN points 22 Jul 08
  1. A critical security vulnerability in DNS systems poses a serious threat to stealing online information and controlling internet activities.
  2. DNS, or Domain Name System, is crucial in mapping computer addresses to human-readable names on the internet.
  3. Temporary solution to mitigate the risk includes switching to DNS servers like OpenDNS, which have already fixed the vulnerability.
Get a weekly roundup of the best Substack posts, by hacker news affinity: