nanog mailing list archives

Re: Schneier: ISPs should bear security burden


From: Valdis.Kletnieks () vt edu
Date: Mon, 02 May 2005 13:35:01 -0400

On Mon, 02 May 2005 13:16:40 EDT, Joe Maimon said:

Thats not quite what I was asking. Would you not have preferred being 
able to do all the above simply by being able to assume that all these 
"dialup" systems would not have any RDNS?

Not having any RDNS would help, but...

Given a choice between ISP using unpredictable naming patterns or no 
name for dialup ranges, what would your preference be?

I'd prefer unpredictable - because as squirrelly *that* is, it's better than
the mess we'll see when the clueless bozos decide that having an internally
visible RDNS is useful to them, and they botch deploying split views for
inside and outside.. over and over in myriad different ways.... 

Attachment: _bin
Description:


Current thread: