Skip to content

Comment on Zone Dumping via DNSSECparent

Comments

NSEC3 is not much better! It's usually a simple iterated hash, of the sort Unices used in the 1990s before the invention of bcrypt, so they can cracked the same way a 1990s password file would be.

Yes, it's not much better, but it's better than nothing. It'll at least make people work a little.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.