Hacker News new | ask | show | jobs
by fanf2 2132 days ago
DNSSEC allows a recursive DNS server to absorb these Google Chrome junk queries: the resolver can use a secure proof of nonexistence to answer the junk query from cache. Much more efficient, and works to absorb junk traffic in any domain signed with NSEC, not just the root. https://tools.ietf.org/html/rfc8198 https://www.potaroo.net/ispcol/2019-04/root.html