Live data from Hacker News

HE.net problem

mailman.nanog.org

41–43 of 43 posts

Re: HE.net problem

#41
post #3

Is there some context that would aid in understanding this? Because it doesn't make sense.

Hurricane Electric (HE) provides, among other things, DNS services. When a domain is placed in `clientHold`, as has happened to HE due to a spurious phishing report, it causes the domain to no longer resolve. So the DNS records for HE and all of HE's customers are gradually becoming unresolvable as caches expire.

I guess this is one of the reasons AWS uses multiple domains in different TLDs for it's customer's name servers in route53[1]

A provider going rouge or a domain expiring will probably still leave 3 perfectly working.

[1] eg one of mine has awsdns-21.com, awsdns-50.co.uk, awsdns-11.net and awsdns-42.org

Re: HE.net problem

#42

Earlier quoted context omitted.

Please elaborate, how would block chain solve this problem?

There's a number of DNS-like protocols on blockchain, e.g. ENS (Ethereum Name System - https://ens.domains/ ), Handshake ( https://handshake.org/ ). They provide same functionality as DNS[sec]. You are not at whim of a corpo, nobody can suspend you, corrupting or hijacking records is pretty much impossible...

That sounds like an excellent feature. Especially for phishing and other scammers who need bulletproof hosting.

Re: HE.net problem

#43

Earlier quoted context omitted.

There's a number of DNS-like protocols on blockchain, e.g. ENS (Ethereum Name System - https://ens.domains/ ), Handshake ( https://handshake.org/ ). They provide same functionality as DNS[sec]. You are not at whim of a corpo, nobody can suspend you, corrupting or hijacking records is pretty much impossible...

That sounds like an excellent feature. Especially for phishing and other scammers who need bulletproof hosting.

Phishing should be handled on a separate level.

There are already many anti-phishing solutions: Chrome has a built-in phishing database, it shows a warning in place of a phish web site. Many VPN and anti-virus software packages come with bad site blockers, it can be done on DNS resolver level, etc.

This is a free market solution: different vendors can compete in phish detection, and users can choose one which works the best.

There's really no need for TLD provider to do this.

And we see why it's a bad idea: a mistake can lead to thousands of legitimate sites being kicked off.

Why are you advocating a solution which is clearly inferior?

Post reply on HN