Live data from Hacker News

Paul Vixie thinks more people should be running their own DNS servers

businessinsider.com

111–120 of 155 posts

Re: Paul Vixie thinks more people should be running their own DNS servers

#111
post #20

More people should be running their own mail servers, their own web servers, their own IRC servers, etc. But I don't think we are ever going back to that direction. The arguments and benefits for running one locally are not enough the trouble as well. Performance? Due to DNS caching at the resolver level, it is probably faster to use Google's 8.8.8.8 or CloudFlare's 1.1.1.1, than anything local (where all dns request…

> Performance? Due to DNS caching at the resolver level,

Not sure about the validity these arguments. Yes, Google is likely to have more cached data than you, but they can also be a half a country or two away.

In my experience caches matter less than one might think, since more popular data is usually the one that's low latency anyway.

> Privacy? With DNS over TLS/DNS over HTTPS, your ISPs can't see

Let's agree on one thing: That surf data is a lot more valuable to Google than most other actors, including your ISP, because they're the ones in a position to monetize it.

Your ISP has more data than they know what to do with anyway. Should they try to monetize it despite the murky legal waters (they really wouldn't want to knowingly help copyright infringement, for example), the realistic option would be for them to sell it to someone very much like Google. It should not come as a surprise that the latter is happy to shortcut the process.

Re: Paul Vixie thinks more people should be running their own DNS servers

#112
post #87

I agree with Paul Vixie. The internet, IMO, is not a playground for large corporations. What originally made the Internet amazing was the participatory nature of it. As it started 'standardizing' or 'accruing', autonomy was lost in the pursuit of efficiency. Today, 2-3 corporations are just trying to own the internet, and this needs to stop. I favour a participation in the Internet than what it is today. Okay, so how…

What's wrong with opkg install unbound? It's robust, doesn't require maintenance, and already available an an optional install in OpenWRT.

The reason people don't use it is probably just that it isn't default. Some captive portals mess with DNS resolution and it's probably easier for OpenWRT to just let them.

Re: Paul Vixie thinks more people should be running their own DNS servers

#113
post #20

More people should be running their own mail servers, their own web servers, their own IRC servers, etc. But I don't think we are ever going back to that direction. The arguments and benefits for running one locally are not enough the trouble as well. Performance? Due to DNS caching at the resolver level, it is probably faster to use Google's 8.8.8.8 or CloudFlare's 1.1.1.1, than anything local (where all dns request…

Is there resolver with Tor proxy? I love being able to use onion websites from browser.

Re: Paul Vixie thinks more people should be running their own DNS servers

#114
post #20

More people should be running their own mail servers, their own web servers, their own IRC servers, etc. But I don't think we are ever going back to that direction. The arguments and benefits for running one locally are not enough the trouble as well. Performance? Due to DNS caching at the resolver level, it is probably faster to use Google's 8.8.8.8 or CloudFlare's 1.1.1.1, than anything local (where all dns request…

Google cache only exists at local nodes in the cluster behind 8.8.8.8; chances you hitting the same node behind 8.8.8.8 for non fb like domains are slim.

Re: Paul Vixie thinks more people should be running their own DNS servers

#115
post #87

I agree with Paul Vixie. The internet, IMO, is not a playground for large corporations. What originally made the Internet amazing was the participatory nature of it. As it started 'standardizing' or 'accruing', autonomy was lost in the pursuit of efficiency. Today, 2-3 corporations are just trying to own the internet, and this needs to stop. I favour a participation in the Internet than what it is today. Okay, so how…

What's wrong with opkg install unbound? It's robust, doesn't require maintenance, and already available an an optional install in OpenWRT. The reason people don't use it is probably just that it isn't default. Some captive portals mess with DNS resolution and it's probably easier for OpenWRT to just let them.

> What's wrong with opkg install unbound? It's robust, doesn't require maintenance,

Good joke. It's written in C, so in addition to typical protocol/logic flaws, it'll have its share of security and memory leak problems. No maintenance? Have a look at https://nlnetlabs.nl/svn/unbound/tags/release-1.9.1/doc/Chan... and its security advisories... Regular updates are necessary.

Re: Paul Vixie thinks more people should be running their own DNS servers

#116
post #103

Earlier quoted context omitted.

Regarding mailservers, it’s feasible to run one at home. But many people rely on spamlists, ie lists of ips known to relay spam. The proble with this is twofold: 1. Some people just took the authority to decide who sends spam and who does not. If you get on one of those lists, usually you have to get in touch and pay to get out. 2. Such people usually include residential ip subnets by default, for no technical reason…

> 2. Such people usually include residential ip subnets by default, for no technical reason whatsoever. Are you talking about residential or about dynamic? Because there kinda is a reason for this for dynamic addresses (PC malware sending spam, and the impossibility to list the particular affected PC because it's constantly changing addreses, so you only can block all the addresses those PCs could be using). If you d…

Where do you rent the VPS? Example from personal experience: Yahoo and Hotmail block DigitalOcean IPs outright. At least they have the decency to reject your mail at delivery, not spamhole it.

Practical DIY SMTP is a lost battle. Unless you're in it for the experience of the hosting itself.

Re: Paul Vixie thinks more people should be running their own DNS servers

#117

Earlier quoted context omitted.

Disclaimer: I work for Google, but not on DNS or Gmail. > Now, Google does claim they don't track DNS requests. But consider why that is? Once upon a time they didn't scan Gmail content either, but that was before GMail dominated the webmail space. You seem to assume that it's a singular organization with a unified agenda, but this really isn't the case. It's the same thing about when folks assume Google looks at you…

I am having a hard time with the do not read email part here. Let me tell you why. 1. I do not use google for DNS 2. I do not use chrome. I use firefox with ad blocking 3. I only browse in private browsing mode 99% of the time. 4. I have a script that updates a block list of 10s of 1000s IPs for ad and tracking blocking, etc into my host file. So I order a box of cigars. Confirmation is to a gmail account. Next day I…

There’s a difference between saying we don’t scan the emails and saying we don’t track the metadata either. So if you bought from an online tobacconist rather than amazon they wouldn’t need to scan the contents.

Re: Paul Vixie thinks more people should be running their own DNS servers

#118
post #73

Earlier quoted context omitted.

Sure sucks to live in New Zealand right now, doesn't it?

The block is a minor inconvenience. I'm okay with it as long as it is a temporary thing.

I'm not. It tells me I can't trust my phone company to reliably provide the internet access I pay them for: who knows what they'll try to block next? I made a complaint, and got a response that quoted the terms of use which say they can mess with traffic if they want to. I know that, and my position is they shouldn't half-assedly try to police content. So, I installed a VPN on my phone.

Re: Paul Vixie thinks more people should be running their own DNS servers

#119
post #104

Earlier quoted context omitted.

> One other catch is that your ISP might block you for not using their DNS; BT (UK ISP) did this Erm ... what? How does that work? If they don't see DNS requests from you at their resolver for a week, they disable your connection?!

What happened is going online resulted in everything being redirected to a BT page saying you're not using our DNS and to change settings so you do. Some googling revealed a few people who'd had the same issue and found the (obscure) page that allowed you to undo the block. I assume they detected it simply by seeing DNS queries going to non-BT servers. Note this was a few years ago when it was pretty common for PC ma…

"N.B. I also recall BT redirecting requests for non-existent domains to some partner of theirs, I assume experimentally as I haven't seen or heard of that for a while"

They are still doing this. I ran into it just yesterday. They do however make it very easy (click a couple of links) to turn it off.

Re: Paul Vixie thinks more people should be running their own DNS servers

#120
post #88

Earlier quoted context omitted.

This is anecdotal but I decided to host my own sites. I bought the cheapest droplet from digital ocean that I could and I set it up running Fedora. Then I installed Apache, MySQL and PHP so I could run some wordpress sites. The server kept running out of memory and shutting down MySQL so my sites stopped working. I started to learn how to read logs and saw that there is a huge amount of malicious activity directed at…

Move mysql to a separate droplet. vultr: $2.50 otherwise you have to change mysql defaults to get things to fit. Great tutorials are out there in general reduce your workers/processes. Why do you need dkim or dmarc to send to gmail? If you send a test php mail does gmail pick it up?

If I send a test email with postfix - gmail rejects it and gives me a link to their page explaining why I need to add a bunch of stuff so they know I'm not spamming or fishing. Specifically I get this:

gmail-smtp-in.l.google.com[173.194.207.27] said: 550-5.7.1 This message does not have authentication information or fails to pass 550-5.7.1 authentication checks. To best protect our users from spam, the 550-5.7.1 message has been blocked. Please visit 550-5.7.1 https://support.google.com/mail/answer/81126#authentication for more 550 5.7.1 information. d203si1756652qkb.228 - gsmtp (in reply to end of DATA command)

there are tons of guides on troubleshooting mysql resource issues. Are they great? I don't know. Have I tried what is mentioned in many of them? Yes. I still have issues. I don't think it's just mysql though. I think it is a lot of little things that I'm slowly eliminating one by one.

Post reply on HN