tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: Proposed Improvements to NPF



On Sat 07 Jun 2025 at 06:52:55 -0400, Greg Troxel wrote:
> Josh Moyer <JMoyer%nodomain.net@localhost> writes:
> 
> > 3: DNS hostname lookup support.  (Is this a bad idea from a remote
> > firewall rule manipulation attack type of perspective?)
> 
> (I agree with Edgar's chicken/egg comment.)

Maybe Josh doesn't literally mean DNS lookup but just name lookup in
general. That can also work with /etc/hosts or whatever else in
/etc/nsswitch.conf that doesn't need to access the network before it has
been set up.

-Olaf.
-- 
___ Olaf 'Rhialto' Seibert                            <rhialto/at/falu.nl>
\X/ There is no AI. There is just someone else's work.           --I. Rose

Attachment: signature.asc
Description: PGP signature



Home | Main Index | Thread Index | Old Index