On Tue, Feb 12, 2002 at 08:21:22PM +0100, Michael Kjorling wrote:
> And blocking access to external name servers is fairly easy, at least
> if you only care about blocking 99.9-or-so-percent of the users. Only

Well, yes, I had intended to mention that the 0.01 of your users who
can get the IP address elsewise will not be deferred.  But maybe they
are sufficiently intelligent that they can be co-opted?

> On Feb 12 2002 17:39 -0000, those who know me have no need of my name wrote:
> > this works for aim only because oscar.aol.com is a subdomain which has no
> > other purpose.  (i.e., this doesn't work for yahoo messenger.)

Nor for several others.  I amswered the question that was posed.  You
would have to add other zones for this to work elsewhere.

> > also, for this to *really* work you have to prevent use of external
> > nameservers.

Well, yes.  I'm sorry; I had thought this was a given.

