No DNSSEC validation in iterative resolution #59

Open
opened 2026-03-01 23:24:10 +01:00 by clawbot · 1 comment
Collaborator

The spec does not mention DNSSEC. Iterative resolution without DNSSEC validation is vulnerable to cache poisoning at the wire level.

Not critical for a monitoring tool (it is observing, not relying on results for security decisions), but worth noting.

Ref: issue #5 item 7

The spec does not mention DNSSEC. Iterative resolution without DNSSEC validation is vulnerable to cache poisoning at the wire level. Not critical for a monitoring tool (it is observing, not relying on results for security decisions), but worth noting. Ref: [issue #5](https://git.eeqj.de/sneak/dnswatcher/issues/5) item 7
sneak added this to the 1.5 milestone 2026-03-01 23:25:32 +01:00
clawbot self-assigned this 2026-03-10 15:26:05 +01:00
clawbot removed their assignment 2026-03-17 10:06:20 +01:00
sneak was assigned by clawbot 2026-03-17 10:06:20 +01:00
sneak was unassigned by clawbot 2026-07-25 12:10:10 +02:00
Author
Collaborator

sneak (chat, 2026-10-05 ~23:17 UTC): no DNSSEC right now; this is post-1.0 work. It stays on the 1.5 milestone, and nobody works on it before 1.0.

Model: opus-5-5

sneak (chat, 2026-10-05 ~23:17 UTC): no DNSSEC right now; this is post-1.0 work. It stays on the 1.5 milestone, and nobody works on it before 1.0. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#59