highlight: damage in the DNS system it gets worse... millions of illegitimate (spec-violating) updates per day to DNS root system spectroscopy analysis of RFC1918 updates caida paper submitted to sigmetrics2003 dynamic DHCP deployed since 1996 RFC1918 updates coming from DHCP/nameservers should not leak outside local site millions a day getting to root name servers (whee) --> AS112 project anycast to offload roots anycast servers dedicated to dealing with updates (tossing) experimenting at F-root first, expanding to others slowly logfiles allows us to analyze root causes (npi)