The one BIG mistake you are making with DNS security today

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

An in-depth interview with Cricket Liu, co-author of NIST Special Publication 800-81 (Secure DNS Deployment Guide), covering the full spectrum of DNS security. Key topics include: the difference between encrypted DNS (DoT, DoH, DoQ) and DNSSEC, protective DNS using Response Policy Zones (RPZ) to block malware C2 and phishing domains, DNS infrastructure hardening against DDoS amplification attacks, DNS hygiene issues like dangling CNAME records (illustrated by a real CDC.gov subdomain hijack), typosquatting and homograph attacks, and quantum computing implications for DNS cryptography. The top three recommendations are: implement protective DNS, secure your DNS infrastructure, and prepare for encrypted DNS adoption.

58m watch time

Sort: