Skip to content

Comment on Encrypted DNS and NTP = Deadlockparent

Comments

Another reason it's nonsensical: when a DNS response is too large to fit in the payload of a UDP datagram, the server sets the TC bit in the response header (alongside whatever truncated results it feels like including), notifying the client of the truncation. The client optionally (but SHOULD) falls back to retrying the query over TCP.

https://serverfault.com/a/698254

Slowly looks at musl's direction.

(musl doesn't even try DNS/TCP after receiving a TC packet)

Yes, this is a pretty grave flaw.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.