
3/4/2016 · Dani Grant
What this post added
This post details Cloudflare's technical approach to mitigating DNS amplification attacks by optimizing DNS packet sizes. It introduces the adoption of ECDSA for smaller DNSKEY sets, comparing its size and security benefits to RSA. It also explains the deprecation of the ANY query type and its role in reducing large DNS responses, thereby preventing abuse for DDoS attacks. The post highlights the use of assembler optimizations for ECDSA signing speed and the creation of an Internet Draft to standardize the deprecation of ANY queries.