Add change note

This commit is contained in:
Owen Mansel-Chan
2024-06-14 13:35:27 +01:00
parent 878867205e
commit 059ef42f41

View File

@@ -0,0 +1,4 @@
---
category: minorAnalysis
---
* We previously considered reverse DNS resolutions (IP address -> domain name) as sources of untrusted data, since compromised/malicious DNS servers could potentially return malicious responses to arbitrary requests. We have now removed this source from the default set of untrusted sources and made a new threat model kind for them, called "reverse-dns".