Live data from Hacker News

Anonymous plans to take down the 13 root DNS servers that power the Internet?

pastebin.com

61–70 of 108 posts

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#61

Earlier quoted context omitted.

So could organizations build their own Root NS cluster and be added to the 13 that already exist? Do I misunderstand something as to why there are only 13, who controls them, etc?

And so Google Public DNS is not really related to these Root NS then. They just simply offer it as a service for those that want to use it.

Google's DNS offering has nothing to do with the root servers.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#62
post #12

Now, I'm thinking about the order of DNS requests.. Local Hosts -> Router -> ISP/OpenDNS/etc -> On out to the Root Servers. Now wouldn't make DNS caching make this attack only partially effective really...if it even worked?

The point is to be heard, not to destroy anything in particular. They're just trying to get attention.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#63
post #57
post #44

Earlier quoted context omitted.

Did you seriously just ask how the web works, then complain about ignorant people who don't know how the web works...? What does hackers using DDoS to knock a service offline have to do with it being free/open? Everything isn't about SOPA/ACTA/et al...

no. are you really trying to start an argument? clearly, you knew what i meant. there is a difference between a web developer who did not understand some specifics regarding a protocol and a "average joe" user who does not even know what a protocol is.

Try not to take this personally, but in this context there's apparently not as much difference as you seem to think. Neither of you (as evidenced by your question) knew enough about DNS to fully understand the implications of what the article was saying. At best you knew enough to know what question to ask.

My point is actually that there's no reason average users need to know this stuff. Any more than there's a need for them to know what a CV boot is on their car. They know if the car makes a weird noise going around corners, call a mechanic. They know if they get errors on "teh Googlez", to call their ISP.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#65

Earlier quoted context omitted.

The pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)

In my experience many ISPs do the exact opposite, and inflate cached TTLs up to a week. Makes migrations a pain in the ass.

Please prove this assertion by posting the address of a resolver that behaves as you describe.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#67

Earlier quoted context omitted.

The pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)

Most ISP's dns cache servers honor the TTL defined in the authoritative SOA records, unless is 1 minute or less. I think the average TTL time for a dns zone would be measured in minutes. It needs to be that low in order to do SRV load-balancing, A/B testing, etc. In any case, in the highly unlikely event that they manage to overload the 13 servers, there's plenty of time for every domain to temporarily extend the TTL…

The negative cache time is defined by the SOA minimum field. Forward cache times are defined at the RR set level.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#69

Earlier quoted context omitted.

It's not just this. Every single time a new link is posted about Anonymous it's some form of digital terrorism. It has barely a purpose and only serves to disrupt the masses. They even have made threats that they would do X if Y isn't done. This is terrorism to me.

This is a serious question: Are you actually in a state of terror by this Pastebin entry, or are you just saying it's rhetorical 'terrorism'?

oh to be an agent provocateur these days! post on pastebin and be home in time for dinner. tomorrow, enjoy the "news" articles calling for a more "secure" internet ...

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#70
post #43

And they are going to get around anycast redundancy how? [0] Also, what consumer level ISP allows egress of packets with a spoofed source IP? [0] http://www.icann.org/en/announcements/factsheet-dns-attack-0...

TFA recommends using VPN (which I assume has fewer restrictions than residential ISPs), or TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).

[deleted]
Post reply on HN