What is Nostr?
Jan Schaumann /
npub1kvy…edh2
2024-02-15 18:04:31

Jan Schaumann on Nostr: You may have seen talk of the "#KeyTrap" #DNSSEC vulnerability in the last few days, ...

You may have seen talk of the "#KeyTrap" #DNSSEC vulnerability in the last few days, with patches pushed for e.g., bind, unbound, knot, etc. in a well coordinated effort across the #DNS community and industry.

In a nutshell: you could DoS a validating resolver by causing it to perform excessive expensive signature validations.

The research team has now published the technical paper:
https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdf

ISC has a good summary here:
https://www.isc.org/blogs/2024-bind-security-release/
Author Public Key
npub1kvy8enal7npw9ct28tc53d4r5fl7q7a3ua3gku22z8jlyec37f3snmedh2