* Potential opportunities for attackers: long TTL values (lingering effects), short TTL values (hard to catch the culprit), relying on older, unpatched versions of nameserver software), or building in less redundancy (for affordability)
+
* Potential opportunities for attackers:
+
** long TTL values (lingering effects),
+
** short TTL values (hard to catch the culprit),
+
** relying on older, unpatched versions of nameserver software),
+
** building in less redundancy (for affordability),
+
** using all authoritative domain servers on the same IPv4 sub-network or physical network, and
+
** fate sharing.<ref>[https://community.icann.org/display/DSFI/DSFI+TSG+Final+Report?preview=/176623416/176623417/DSFI-TSG-Final-Report.pdf DSFI-TSG Final Report, pg. 23, ICANN Community]</ref>