Light

Episode #1010 Quiz

DNS Over TLS
Date: 2025-01-28 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

Security Now! #1010 explores DNS over TLS (DoT), detailing its implementation challenges compared to traditional DNS over UDP, notably the overhead of TCP connection and TLS handshake state management on big DNS servers leading to impatient connection drops. Encrypted DNS mitigates privacy risks but requires bursty, amortized queries for performance.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the specific DNS misconfiguration error in Mastercard's DNS servers that persisted for nearly five years?
Question 2: Why do DNS over TLS (DoT) servers tend to drop connections quickly after establishment?
Question 3: How does the typical web browser's DNS query behavior make the performance cost of DNS over TLS feasible?
Question 4: What key limitation did the attacker pose by registering the misnamed "akam.ne" domain for Mastercard's DNS?
Question 5: What was the unexpected discovery made when benchmarking DNS over TLS compared to traditional DNS over UDP?
Cancel