netsec-sig - Re: [Security-WG] DNS Location record question
Subject: Internet2 Network Security SIG
List archive
- From: Chris Wilkinson <>
- To: "" <>
- Subject: Re: [Security-WG] DNS Location record question
- Date: Tue, 5 Sep 2017 13:53:08 +0000
- Accept-language: en-US
- Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
- Ironport-phdr: 9a23:BYFrbxBwIfpPP6ullVcAUyQJP3N1i/DPJgcQr6AfoPdwSPX/pcbcNUDSrc9gkEXOFd2CrakV26yO6+jJYi8p2d65qncMcZhBBVcuqP49uEgeOvODElDxN/XwbiY3T4xoXV5h+GynYwAOQJ6tL1LdrWev4jEMBx7xKRR6JvjvGo7Vks+7y/2+94fdbghMhzexe69+IAmrpgjNq8cahpdvJLwswRXTuHtIfOpWxWJsJV2Nmhv3+9m98p1+/SlOovwt78FPX7n0cKQ+VrxYES8pM3sp683xtBnMVhWA630BWWgLiBVIAgzF7BbnXpfttybxq+Rw1DWGMcDwULs5Xymp4aV2Rx/ykCoJNyA3/nzLisJ+j6xbrhCupx1jzIDbb46YL+Z+cbjYfd8GWWZNQsRcWipcCY28dYsPCO8BMP5Goon9vVsOrAC+DhSsC+Puzj9IhX723ash0+QmFwHNwQstEM4AsXTVqNX1N6YSUeauzKnPyzXOdPJW2THh6IfWaBAhp++DXa5ufcbL10YgCh7Fg0yWpIf4MT2V0eENvHKa7+pmTe+vjXAoqg9xozWh2MsjkI7JiZgPxlDC6yp53IA4LsC7Rk5jedOoDoFfuz2HO4ZzX88uXnxktSM0yrAJpZK3YC0HxZY5yBPQb/GKdo2F7gz/WOqNOTt1hXZodKiiixu880Ws0PPwWtSw3VpQsyZIkNbBu3YQ3BLJ8MeHUOFy/kK51DaPyQ/T7uZELFgsm6fHLJAt3rA9moMdv0rEECL6gUL2g7SIeUk+/eio9vjnba7hpp+BMY97lxvyMrw0msy4HeQ3LBQBX3Sa+eS70r3v50r5QKhWjv0ylanZt5PaKd4Hqa6+Bg9Zyocj6xChADe6yNkUg2MIIE5YdB+CkoTlJkzCLfX2Dfqwn1igjDJmyvLYMbDuBpjAK33OnKn9cbph80JczRA8zdFb55JaELEBJ/fzV1ftu93WDx85Nw+0w+fhCNVm0YMeX3mCAq6fMKPOr1CI/OQvLPeQZIMLojryNeUq5+P2gX8jhVAdZbWp3YcQaH2gBfRpPVmWYWf2gtcADWcLvhMyTeLliFCZVT5TZm2yX74n5j0lEo6mDIHDRpyzj7yb2ie0AIFWan5cBl+SDHjoatbMZ/BZIjmfKdJ7kyAVEKeuY44nyRy0sgLmkfxqIveesnkDuJn+ztlp9qjMmjkz8yB5FcKQzzvLQm1pyDAmXTgziYt/u01mgmiC1at5hedfE5QH7OxIVgQ7M4XbycR7Dcz/QATMYo3PRVq7FIb1SQotR848loddK312HM+v20jO
- Spamdiagnosticoutput: 1:0
+1
I believe, Perfsonar also uses DNS LOC records.
A dedicated attacker can easily glean from past social media where our sites
are and that we are partnered with Level(3).
As Steve notes, knocking down the precision may be the better approach here.
On 9/5/17, 9:46 AM, "Steven Wallace"
<
on behalf of
>
wrote:
I use them from time to time (visual traceroute)
I suspect researchers may as well. IMO, the security list is probably not
the best place to ask if they’re used.
The LOC below record lists 10,000 meters as its horizontal precision,
however the coordinates' precision is about 100 meters.
IMO, leave them, but knock the precision of the lat/long down to .01
rather than .001.
ssw
> On Sep 5, 2017, at 9:26 AM, Paul Howell
<>
wrote:
>
> Hi,
>
> Currently Internet2 publishes location information for each router in
the respective DNS records. Here’s an example:
>
> rtsw.newy32aoa.net.internet2.edu. 3600 IN LOC 40 43 12.248 N 74 0
18.716 W 0.00m 1m 10000m 10m
>
> Would anyone that is using these records please message me? If they
are no longer needed, we may remove them.
>
> Regards,
> Paul
>
>
- [Security-WG] DNS Location record question, Paul Howell, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Jason Zurawski, 09/05/2017
- Re: [Security-WG] DNS Location record question, James Deaton, 09/05/2017
- Re: [Security-WG] DNS Location record question, Chris Wilkinson, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Matthew J Zekauskas, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Chris Wilkinson, 09/05/2017
- Re: [Security-WG] DNS Location record question, Jeff Bartig, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, Matthew J Zekauskas, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
- Re: [Security-WG] DNS Location record question, Michael H Lambert, 09/05/2017
- Re: [Security-WG] DNS Location record question, David Farmer, 09/05/2017
- Re: [Security-WG] DNS Location record question, Paul Howell, 09/05/2017
- Re: [Security-WG] DNS Location record question, Steven Wallace, 09/05/2017
Archive powered by MHonArc 2.6.19.