You are not logged in.

#1 2019-01-14 21:05:42

brianbaligad
Member
Registered: 2013-08-12
Posts: 22

systemd-resolved sane defaults

Sorry if this has been discussed previously, but I'm surprised to see mDNS and LLMNR by default in systemd-resolved. These protocols assume a trusted LAN, but since DNS is unauthenticated that makes it vulnerable to a mitm.  I'm sure everyone in this community checks and changes configuration in each new package they install accordingly, but it may be wise to have them off by default in light of the tyranny of the defaults?

Offline

Board footer

Powered by FluxBB