Skip to main content

This is a new website theme. Help me improve it and give your feedback (opens in a new tab).

Planet FSFE

A Solution for Authoritative DNS

I’ve been thinking about improving my DNS setup. So many things will use e-mail verification as a backup authentication measure that it is starting to show as a real weak point. An Ars Technica article earlier this year talked about how “[f]ederal authorities and private researchers are alerting companies to a wave of domain hijacking attacks that use relatively novel techniques to compromise targets at an almost unprecedented scale.”

The two attacks that are mentioned in that article, changing the nameserver and changing records, are something that DNSSEC could protect against. Records wouldn’t have to be changed on my chosen nameservers, a BGP-hijacking could just give another server the queries for records on my domain instead and then reply with whatever it chooses.

Summer School on Internet Path Transparency Measurements


This post was originally published at the MAMI Project blog.


On June the 11th the Electronics Research Group hosted the MAMI Summer School on Internet Path Transparency Measurements in Aberdeen, Scotland. This consisted of a few hands-on workshops, with participation both on-site and remote via video conference.

The summer school started with Korian and Justin demonstrating Tracebox through a variety of topologies. The participants then worked on their own trying to uncover middleboxes and hidden topologies using a variety of tools, including tracebox and paris-traceroute.