Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] DNS Location record question

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] DNS Location record question


Chronological Thread 
  • From: Chris Wilkinson <>
  • To: "" <>
  • Subject: Re: [Security-WG] DNS Location record question
  • Date: Tue, 5 Sep 2017 13:53:08 +0000
  • Accept-language: en-US
  • Authentication-results: internet2.edu; dkim=none (message not signed) header.d=none;internet2.edu; dmarc=none action=none header.from=internet2.edu;
  • Ironport-phdr: 9a23:BYFrbxBwIfpPP6ullVcAUyQJP3N1i/DPJgcQr6AfoPdwSPX/pcbcNUDSrc9gkEXOFd2CrakV26yO6+jJYi8p2d65qncMcZhBBVcuqP49uEgeOvODElDxN/XwbiY3T4xoXV5h+GynYwAOQJ6tL1LdrWev4jEMBx7xKRR6JvjvGo7Vks+7y/2+94fdbghMhzexe69+IAmrpgjNq8cahpdvJLwswRXTuHtIfOpWxWJsJV2Nmhv3+9m98p1+/SlOovwt78FPX7n0cKQ+VrxYES8pM3sp683xtBnMVhWA630BWWgLiBVIAgzF7BbnXpfttybxq+Rw1DWGMcDwULs5Xymp4aV2Rx/ykCoJNyA3/nzLisJ+j6xbrhCupx1jzIDbb46YL+Z+cbjYfd8GWWZNQsRcWipcCY28dYsPCO8BMP5Goon9vVsOrAC+DhSsC+Puzj9IhX723ash0+QmFwHNwQstEM4AsXTVqNX1N6YSUeauzKnPyzXOdPJW2THh6IfWaBAhp++DXa5ufcbL10YgCh7Fg0yWpIf4MT2V0eENvHKa7+pmTe+vjXAoqg9xozWh2MsjkI7JiZgPxlDC6yp53IA4LsC7Rk5jedOoDoFfuz2HO4ZzX88uXnxktSM0yrAJpZK3YC0HxZY5yBPQb/GKdo2F7gz/WOqNOTt1hXZodKiiixu880Ws0PPwWtSw3VpQsyZIkNbBu3YQ3BLJ8MeHUOFy/kK51DaPyQ/T7uZELFgsm6fHLJAt3rA9moMdv0rEECL6gUL2g7SIeUk+/eio9vjnba7hpp+BMY97lxvyMrw0msy4HeQ3LBQBX3Sa+eS70r3v50r5QKhWjv0ylanZt5PaKd4Hqa6+Bg9Zyocj6xChADe6yNkUg2MIIE5YdB+CkoTlJkzCLfX2Dfqwn1igjDJmyvLYMbDuBpjAK33OnKn9cbph80JczRA8zdFb55JaELEBJ/fzV1ftu93WDx85Nw+0w+fhCNVm0YMeX3mCAq6fMKPOr1CI/OQvLPeQZIMLojryNeUq5+P2gX8jhVAdZbWp3YcQaH2gBfRpPVmWYWf2gtcADWcLvhMyTeLliFCZVT5TZm2yX74n5j0lEo6mDIHDRpyzj7yb2ie0AIFWan5cBl+SDHjoatbMZ/BZIjmfKdJ7kyAVEKeuY44nyRy0sgLmkfxqIveesnkDuJn+ztlp9qjMmjkz8yB5FcKQzzvLQm1pyDAmXTgziYt/u01mgmiC1at5hedfE5QH7OxIVgQ7M4XbycR7Dcz/QATMYo3PRVq7FIb1SQotR848loddK312HM+v20jO
  • Spamdiagnosticoutput: 1:0

+1

I believe, Perfsonar also uses DNS LOC records.

A dedicated attacker can easily glean from past social media where our sites
are and that we are partnered with Level(3).

As Steve notes, knocking down the precision may be the better approach here.

On 9/5/17, 9:46 AM, "Steven Wallace"
<
on behalf of
>
wrote:

I use them from time to time (visual traceroute)

I suspect researchers may as well. IMO, the security list is probably not
the best place to ask if they’re used.

The LOC below record lists 10,000 meters as its horizontal precision,
however the coordinates' precision is about 100 meters.

IMO, leave them, but knock the precision of the lat/long down to .01
rather than .001.

ssw


> On Sep 5, 2017, at 9:26 AM, Paul Howell
<>
wrote:
>
> Hi,
>
> Currently Internet2 publishes location information for each router in
the respective DNS records. Here’s an example:
>
> rtsw.newy32aoa.net.internet2.edu. 3600 IN LOC 40 43 12.248 N 74 0
18.716 W 0.00m 1m 10000m 10m
>
> Would anyone that is using these records please message me? If they
are no longer needed, we may remove them.
>
> Regards,
> Paul
>
>






Archive powered by MHonArc 2.6.19.

Top of Page