Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

2a/ ok, I misread what was the intention, maybe it's a good idea then

3/ it's not about "better maintained", it's about trusting the internet on sensitive data, which you should never do, because dns is easily spoofed and nginx resolver was not written to operate in a hostile environment. if you don't have a local caching resolver on your machine (which you should), even trusting your cloud provider dns is better than trusting goog one. nginx documentation even says " To prevent DNS spoofing, it is recommended configuring DNS servers in a properly secured trusted local network. " on http://nginx.org/r/resolver



You're right: checking this out further, the nginx resolver seems to have a bunch of issues [1] which is concerning.

I've modified the config accordingly.

[1] http://blog.zorinaq.com/nginx-resolver-vulns/


Yep - the warning clause in the documentation is there because of those issues.

thanks!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: