Earlier quoted context omitted.
So could organizations build their own Root NS cluster and be added to the 13 that already exist? Do I misunderstand something as to why there are only 13, who controls them, etc?
And so Google Public DNS is not really related to these Root NS then. They just simply offer it as a service for those that want to use it.
Anonymous plans to take down the 13 root DNS servers that power the Internet?
61–70 of 108 posts
Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#62Now, I'm thinking about the order of DNS requests.. Local Hosts -> Router -> ISP/OpenDNS/etc -> On out to the Root Servers. Now wouldn't make DNS caching make this attack only partially effective really...if it even worked?
Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#63Earlier quoted context omitted.
Did you seriously just ask how the web works, then complain about ignorant people who don't know how the web works...? What does hackers using DDoS to knock a service offline have to do with it being free/open? Everything isn't about SOPA/ACTA/et al...
no. are you really trying to start an argument? clearly, you knew what i meant. there is a difference between a web developer who did not understand some specifics regarding a protocol and a "average joe" user who does not even know what a protocol is.
My point is actually that there's no reason average users need to know this stuff. Any more than there's a need for them to know what a CV boot is on their car. They know if the car makes a weird noise going around corners, call a mechanic. They know if they get errors on "teh Googlez", to call their ISP.
Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#64Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#65Earlier quoted context omitted.
The pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)
In my experience many ISPs do the exact opposite, and inflate cached TTLs up to a week. Makes migrations a pain in the ass.
Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#66Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#67Earlier quoted context omitted.
The pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)
Most ISP's dns cache servers honor the TTL defined in the authoritative SOA records, unless is 1 minute or less. I think the average TTL time for a dns zone would be measured in minutes. It needs to be that low in order to do SRV load-balancing, A/B testing, etc. In any case, in the highly unlikely event that they manage to overload the 13 servers, there's plenty of time for every domain to temporarily extend the TTL…
Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#68hmm..and people here on HN say they aren't a digital terrorist group.....
Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#69Earlier quoted context omitted.
It's not just this. Every single time a new link is posted about Anonymous it's some form of digital terrorism. It has barely a purpose and only serves to disrupt the masses. They even have made threats that they would do X if Y isn't done. This is terrorism to me.
This is a serious question: Are you actually in a state of terror by this Pastebin entry, or are you just saying it's rhetorical 'terrorism'?
Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?
#70And they are going to get around anycast redundancy how? [0] Also, what consumer level ISP allows egress of packets with a spoofed source IP? [0] http://www.icann.org/en/announcements/factsheet-dns-attack-0...
TFA recommends using VPN (which I assume has fewer restrictions than residential ISPs), or TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).