Hacker News new | ask | show | jobs
by bortzmeyer 3206 days ago
What makes you tell it looks like DNS poisoning? It if were DNS poisoning, some resolvers would have been poisoned but not all, while, here, everybody saw the attacker's IP address. http://www.bortzmeyer.org/observations-wikileaks.html
1 comments

You may be right - I was basing that information off statements that it was only some users seeing the attack. I wasn't aware of a historic data source that could show otherwise.

Your analysis looks pretty good but I disagree that DNSSEC would have stopped the attack, because many users don't use validating resolvers.