logoalt Hacker News

Borealidtoday at 7:50 AM1 replyview on HN

In order for an attacker to reduce a site's Availability via DNS they must alter the records received by resolvers.

If they can do that, they can just refuse to send the records at all (or mangle them such that they are ignored). DNSSEC makes the situation no worse.

It does, however, increase Integrity.

For the record, the 'A' in CIA refers to resilience against some party's purposeful attempt to make something unavailable. It does not stand for Areliability or Asimplicity.


Replies

akerl_today at 1:07 PM

> For the record, the 'A' in CIA refers to resilience against some party's purposeful attempt to make something unavailable.

That’s pretty clearly not correct.

show 1 reply