Fedora mulls providing a local DNSSEC resolver
Fedora mulls providing a local DNSSEC resolver
Posted May 25, 2014 10:50 UTC (Sun) by tialaramex (subscriber, #21167)In reply to: Fedora mulls providing a local DNSSEC resolver by Comet
Parent article: Fedora mulls providing a local DNSSEC resolver
In the same way that two corporations will try to merge and find that they had both chosen to stick loads of devices into 10.1/16 and none in 10.183/16 because humans are simultaneously stupid AND lazy, with ULA inevitably some idiots will pick values that were easy to remember or convenient for some other reason and then be "surprised" that others did the same.
If you actually use random numbers (hexadecimal dice are pretty cheap, buy a few for your network administrators) then there's no more problem with ULA collisions than with people accidentally flying a 747 into your data centres. You would need about a million randomly generated ULA organisational prefixes to be sharing a "private" network before the statistics are in favour of just one collision (because of the birthday paradox). Somewhere in the first few thousand such prefixes it's time to say "Hey, I don't think this is a private network after all" and get real IPv6 prefixes from your RIR.