<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>bert hubert finally blogs: I bit the bullet and wrote an RFC ('to be')</title>
    <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>code, musings and more</description>
    <item>
      <title>I bit the bullet and wrote an RFC ('to be')</title>
      <description>&lt;p&gt;I&amp;#8217;ve long been a somewhat active member of the relevant DNS mailing lists, &amp;#8216;namedroppers&amp;#8217; and &amp;#8216;dnsop&amp;#8217;, both affiliated with the IETF DNS workgroups.&lt;/p&gt;

&lt;p&gt;I consider myself a bit of an outcast in the DNS community as I don&amp;#8217;t sing the praises of DNSSEC, nor BIND, but I suspect this is not entirely fair as there are quite a number of people who are far more outcast than I am. So I suspect I&amp;#8217;m on the fringe of the DNS community in the sense that I incidentally take part in useful email discussion, either on list or privately with relevant parties.&lt;/p&gt;

&lt;p&gt;I recently called upon nameserver authors and operators to either upgrade their nameserver so it performs adequate anti-spoofing measures, or switch to a nameserver implementation that does (like &lt;a href="http://cr.yp.to/djbdns.html"&gt;tinydns&lt;/a&gt; or of course &lt;a href="http://wiki.powerdns.com"&gt;PowerDNS&lt;/a&gt;).&lt;/p&gt;

&lt;p&gt;This call fell on very deaf ears it appears. The BIND people promised to look into it but as noted then, without an apparant sense of urgency. Not a lot has happened since, except that I&amp;#8217;ve reiterated my recommendation privately to a number of relevant people.&lt;/p&gt;

&lt;p&gt;In the meantime, I&amp;#8217;ve been told the Microsoft nameserver is about 4 times easier to spoof than BIND, but I&amp;#8217;ve been unable to verify this.&lt;/p&gt;

&lt;p&gt;So, I did what I never thought I&amp;#8217;d do, I wrote something intended to be an RFC. In short, this RFC specifies that a recursor MUST implement adequate anti-spoofing measures, and details what this entails.&lt;/p&gt;

&lt;p&gt;Read all about it &lt;a href="http://ds9a.nl/rfc/dns-anti-spoofing.txt"&gt;as old school text&lt;/a&gt; or rendered as &lt;a href="http://ds9a.nl/rfc/dns-anti-spoofing.html"&gt;pretty HTML&lt;/a&gt;. The RFC-compliant output is made possibly by the interesting but quirky tool &lt;a href="http://xml.resource.org/"&gt;xml2rfc&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;I&amp;#8217;ll spend some more time polishing the document before submitting it as an Internet Draft. I also need to figure out the correct procedure to set things in motion.&lt;/p&gt;

&lt;p&gt;I sincerely hope nameservers that are easy to spoof clean up their act quickly, hopefully even before my draft hits the standards track.&lt;/p&gt;</description>
      <pubDate>Tue, 09 May 2006 22:15:00 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:203603a3-fc57-4ef9-a0b3-45eca650c742</guid>
      <author>bert.hubert@netherlabs.nl (bert hubert)</author>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be</link>
      <category>PowerDNS</category>
      <category>Netherlabs</category>
      <trackback:ping>http://blog.netherlabs.nl/articles/trackback/302</trackback:ping>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by bang bros</title>
      <description>Very pleased to read this article!</description>
      <pubDate>Sun, 03 Jun 2007 13:13:32 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:8e1645f1-3dde-47fc-bf2f-da6803676e48</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-134693</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by we live&lt;sp&gt;together</title>
      <description>I can assume this is most poweful blog system!</description>
      <pubDate>Sat, 02 Jun 2007 13:27:42 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:7da04faa-aab2-4760-8a08-5df1bed507a4</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-134198</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by bang bus</title>
      <description>Here is better than anywhere, i probably will stay!</description>
      <pubDate>Thu, 31 May 2007 21:38:40 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:5a30fea7-e4a9-4689-811a-d2421d93d054</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-133259</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by bang bus</title>
      <description>Very nice article, thank you!</description>
      <pubDate>Thu, 31 May 2007 11:43:15 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:17b48d44-9480-4eb5-87a4-f7b24ce063a5</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-132984</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by tera patrick</title>
      <description>I find this article useful for both beginners and skilled users, thank you!</description>
      <pubDate>Tue, 29 May 2007 23:33:59 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:a101e1ee-34e1-4a5e-91f0-1b6024f87b77</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-132210</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by teen models</title>
      <description>Definetely try re-installing apache or try to trace path to server!</description>
      <pubDate>Tue, 29 May 2007 00:11:00 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:a4b55ba6-0473-4189-9905-01e6b8d8e5a0</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-131340</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by my first sex teacher</title>
      <description>Can anyone advice normal hosting provider? i don't need free like blogger, i need paid!</description>
      <pubDate>Mon, 28 May 2007 15:08:37 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:fc71d72b-a828-486b-9916-55d939beeb92</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-130994</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by big naturals</title>
      <description>Compilator for such programms like GenEngineCompile is impossible to install, why?</description>
      <pubDate>Sat, 26 May 2007 16:38:37 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:ca52e83a-27fe-40e3-9348-198e072e3f74</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-129107</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by fee</title>
      <description>a lot of spam</description>
      <pubDate>Tue, 17 Apr 2007 00:01:56 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:91493082-5a60-4c73-a050-fa0eceb31364</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-98421</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by recipricol link</title>
      <description>exchange links link partners backlink
link service exchange program popular link exchange links exchange system
exchange service web link exchange travel links exchange recipricol link</description>
      <pubDate>Wed, 13 Dec 2006 14:28:09 +0100</pubDate>
      <guid isPermaLink="false">urn:uuid:e222d961-2d62-4afe-83c3-dc18afcc232b</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-30041</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by ahu</title>
      <description>They are free to do so. I happen to believe in the power of the GPL to foster cooperation and not just incorporation.</description>
      <pubDate>Sat, 13 May 2006 00:07:22 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:97512a77-7b0f-4563-8cc0-b971f7ce4ffa</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-323</link>
    </item>
    <item>
      <title>"I bit the bullet and wrote an RFC ('to be')" by Leen Besselink</title>
      <description>Here is some food for thought:

If you really think that your solution is more secure and you are serious about making the internet more secure, you should change the license of the recursor so people can include it in there own products. :-)
</description>
      <pubDate>Thu, 11 May 2006 13:34:42 +0200</pubDate>
      <guid isPermaLink="false">urn:uuid:9d643808-e84a-4d49-8311-c8b53b590dbc</guid>
      <link>http://blog.netherlabs.nl/articles/2006/05/09/i-bit-the-bullet-and-wrote-an-rfc-to-be#comment-306</link>
    </item>
  </channel>
</rss>
