Skip to content

Overdoing NSEC3 Hurts

Speaker:
Petr Špaček, Internet Systems Consortium
Date:
Time:
Room:
Side Room
Session:
DNS
Duration:
14 min
Transcript:
View session transcript
Meetecho chat:
View session chat
Type:
Talk
Slides:

Abstract

An NSEC3 configuration with too many iterations leads to excessive work on authoritative servers and resolvers, can be used for DoS attacks, and even opens a downgrade attack path which is not well documented.

In this brief talk we want to alert operators to this danger and evangelize Best Current Practice RFC 9276 which shows how to use NSEC3 in a safe (or less harmful) way.

Recording

Speaker

Petr Špaček

Petr Špaček

Rate this talk

Rating is closed.