Posted Aug 2, 2012 20:51 UTC (Thu) by liljencrantz (subscriber, #28458)
Parent article: The leap second of doom
Jake, who exactly says that "NTP has not generally been seen as a vector for attacks"? My employer handles massive amounts of traffic, and the only possible way to handle network hiccups without going down is to aggressively deadline old queries. As the same query moves from subsystem to subsystem on it's path to completion, keeping the internal clocks of all servers synced is absolutely critical, a task that falls squarely on NTP. We have though hard about what a rouge NTP time source could do to our service and how we can protect ourselves.