nanog mailing list archives

RE: Level(3) DNS Spoofing All Domains


From: "Marshall, Quincy" <Quincy.Marshall () reged com>
Date: Tue, 19 Nov 2019 18:54:56 +0000

On Tuesday, November 19, 2019 1:35 PM, Mike Bolitho <mikebolitho () gmail com> said…
“How many of (my) clients have miss-typed something and sent their data, unknowingly, to a 3rd party host? (Who’s fault 
would that be?)

Yours? They paid you to set up their network properly and you set it up to resolve to Level 3. So if they "unknowingly 
sent their data" to a third party then it would be your fault.”

If I was retained by my clients to setup, design, configure, and/or maintain, our client’s networks. I would completely 
agree with you.
(FWIW, my internal network would not connect to these host even if one of my user’s fat-fingered the URL.)

However, I’m referring to a completely autonomous 3rd party network (Say they type wwww.omb.gov<http://wwww.omb.gov>) 
Can I be expected to anticipate their user’s/APP DEV’s typos?

Lawrence Q. Marshall
---------------------------------------------------------------------------------------
 This email has been scanned for email related threats and delivered safely by Mimecast.
 For more information please visit http://www.mimecast.com
---------------------------------------------------------------------------------------

Current thread: