[Dnssec-deployment] "Two Strikes For the I-root"

Patrik Fältström patrik at frobbit.se
Mon Jun 14 09:30:20 EDT 2010


On 13 jun 2010, at 20.44, Michael Richardson <mcr at sandelman.ca> wrote:

> So, the interesting part is:
>
> dig @dns1.chinatelecom.com.cn. www.facebook.com.
>   ...
>   www.facebook.com.       11556   IN      A       37.61.54.158
>   www.facebook.com.       24055   IN      A       78.16.49.15
>   www.facebook.com.       38730   IN      A       203.98.7.65
>
> and the note that:
>
>   "None of these IP addresses has anything to do with Facebook. In
>   fact, addresses starting with 37 haven't even been allocated by  
> IANA as
>   of this writing. "
>
> Whether or not this is evidence that i-root is serving wrong  
> answers, or
> that packets are being modified in flight, or that "dns1.chinatelecom.com.cn 
> "
> is answering with forged answers is irrelevant.

Correct, if it was not the case that Renesys use this as evidence that  
I-root fiddled with the responses, that people should stop using I- 
root etc.

    Patrik

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://dnssec-deployment.org/pipermail/dnssec-deployment/attachments/20100614/559af8de/attachment.html 


More information about the Dnssec-deployment mailing list