Open Resolver Problems

OK, but we started this discussion about open recursive resolvers,
right?  Securing your recursive resolvers is a very different problem
space from trying to come up with rate limits for your authoritative

In terms of impacts people are feeling today, is most of the pain
coming from open recursive servers being abused by miscreants,
or from miscreants doing spoofed queries against authoritative

The concern Valdis raised about securing recursives while still
being able to issue static nameserver IPs to mobile devices
is an orthogonal problem to Owen putting rate limiters on
the authoritative servers for he.net.  If we're all lighting up
pitchforks and raising torches, I'd kinda like to know at which
castle we're going to go throw pitchforks.