Hacker News new | ask | show | jobs
by 0xquad 1985 days ago
>Raw IPs can be used as well, but that doesn’t negate my point.

And in fact if you have enterprise-wide visibility on DNS requests, you have the opportunity to detect the use of an IP that was not returned in a request. Making it immediately suspect.