I’m absolutely not taking away from that point, sir. I just wanted to jump to the defense of MSDNS since the paper seemed to jump on it as flawed. Every system is flawed with the right backdoors or vulnerabilities to exploit.
We’re already discussing IRONSIDES here internally.
Ah, I see. You are certainly right that MS DNS can be as secure as BIND, I would actually be surprised if BIND didn't actually have statistically more than MS DNS because [IIUC] MS has, over the past few years, been integrating some prover technology into their build-cycle/code-review. -- Of course since they're likely using languages that are highly resistant to analysis (the C-family as a whole) I'd take that with a grain of salt.