<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>An Information Security Place &#187; DNS</title>
	<atom:link href="http://infosecplace.com/blog/category/dns/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosecplace.com/blog</link>
	<description>Commentary on the State of Information Security</description>
	<lastBuildDate>Wed, 23 Jun 2010 11:19:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The DNS oops and a Lindstrom &quot;d&#8217;oh!&quot;</title>
		<link>http://infosecplace.com/blog/2008/07/23/the-dns-oops-and-a-lindstrom-doh/</link>
		<comments>http://infosecplace.com/blog/2008/07/23/the-dns-oops-and-a-lindstrom-doh/#comments</comments>
		<pubDate>Wed, 23 Jul 2008 12:09:11 +0000</pubDate>
		<dc:creator>Michael Farnum</dc:creator>
				<category><![CDATA[DNS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Sheesh]]></category>

		<guid isPermaLink="false">http://infosecplace.com/blog/2008/07/23/the-dns-oops-and-a-lindstrom-doh/</guid>
		<description><![CDATA[OK, so the Matasano people accidentally let everyone know what the DNS flaw was.&#160; I posted my thoughts on that at my CW blog.&#160; But then I read Pete Lindstrom&#8217;s little post about the issue, and I just have to wonder what Pete is thinking.&#160; Pete says this:
Here&#8217;s a thought: If you really want to [...]]]></description>
			<content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="171" alt="image" src="http://infosecplace.com/blog/wp-content/uploads/2008/07/image.png" width="244" align="right" border="0" />OK, so the Matasano people accidentally let everyone know what the DNS flaw was.&#160; I posted my thoughts on that at <a href="http://blogs.computerworld.com/dns_flaw_to_tell_or_not_to_tell">my CW blog</a>.&#160; But then I read <a href="http://spiresecurity.typepad.com/spire_security_viewpoint/2008/07/heres-a-thought-if-you-really-want-to-keep-a-secret.html">Pete Lindstrom&#8217;s little post</a> about the issue, and I just have to wonder what Pete is thinking.&#160; Pete says this:</p>
<blockquote><h5>Here&#8217;s a thought: If you really want to keep a secret&#8230;</h5>
<p>&#8230; I recommend against a press release, <a href="http://www.doxpara.com/?p=1162">blog post</a>, podcast, youtube video, public interviews, and comments. I know this is a bit radical, but I&#8217;m just sayin&#8217;&#8230;</p>
<p>Sort of like &#8211; the people who would <em>really </em>have to kill you if they told you something are smart enough not to tell you in the first place&#8230;</p>
</blockquote>
<p>Wow.&#160; So Mr. Lindstrom, how do you propose that Dan let people know they need to patch their DNS <strong>WITHOUT TELLING THEM?!?!?&#160; </strong>Dan did everything he could not to let anyone but a few select &quot;need-to-know&quot; people about the flaw.&#160; He told them so they could develop patches.&#160; Then he announced it <strong>after</strong> they developed the patches.&#160; He did a great job with this.</p>
<p>What he didn&#8217;t want getting out was the <strong>details</strong> of the attack.&#160; But I am pretty sure Dan knew that this would happen eventually.&#160; There are too many people out there looking at this now for it not to come out.&#160; But hey, a man can hope, right??</p>
<p>So seriously Pete, think about it.&#160; Dan was trying to keep the flaw itself a secret before he announced so patches could get developed, then he announced so people would would know there was a flaw and would patch, and then he was trying to keep the details secret after he announced so people had time to patch.&#160; But he couldn&#8217;t NOT tell people and expect them to patch.&#160; </p>
<p>Vet</p>
]]></content:encoded>
			<wfw:commentRss>http://infosecplace.com/blog/2008/07/23/the-dns-oops-and-a-lindstrom-doh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
