Live data from Hacker News

Chinese RFC proposes separate, independent, national internets and DNS roots

tools.ietf.org

21–30 of 81 posts

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#21
I wonder if they thought about what would happen if Canada, the United States, and the rest of the world adopted this RFC?

For example, lets say an entrepreneur develops a new product and wants to have it manufactured by an outsourced company. Searches for it on Google, but thanks to this RFC the results from China either don't show up, or don't load at all. The entrepreneur therefore opts for a manufacturing company in Des Moines, Iowa.

I guess perhaps the same could happen if only China adopts this RFC, i.e. business people in China who don't know better launch their website on a Chinese only DNS system and wonder why nobody from the rest of the world calls them.

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#22

I can barely read it... the spelling and grammar are terrible. This can NOT be a real effort... can it?

Access to people that write good english can be very hard to get in China, so that is probably not a good indicator of anything in this case.

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#23
Setting aside the motivations for this draft, the idea of removing the one single DNS 'root' is a reasonable one. It acts as a single point of failure for the DNS system and puts the entire DNS hierarchy under the jurisdiction of the United States Department of Commerce. There are already existing alternative roots[1], but no interoperability between them and no standards governing them. Indeed, the IETF is strongly against them at present [2].

With that in mind, let us examine the flaws in the proposal at hand.

* 1. Lettered roots

This proposal puts the existing DNS root under a lettered virtual root above it, with implicit resolution to the local AIP. The existing DNS root locations are ALREADY indexed by letter, so this is a recipe for confusion. Even more importantly, this system _will not scale_: There are 26 possible letters, if drawing from the ASCII set only, which permanently restricts the number of autonomous zones. What happens then?

This could be resolved by using a unique suffix scheme that does not conflict with the existing or requested TLDs, but would make it that much harder to type an external DNS address. yahoo.com.extdomA for general use would be quite unfortunate.

* 2. Who hands out the AIP designations?

If every AIP must have a single unique designation, there must be an organization handing them out. The ICANN would be the obvious choice, but that brings us back around full circle.

* 3. Ownership conflicts

As rfc2826 points out [2], the internet is built on the assumption that domain names are unique. With multiple implicit zones, either the same entity must be able to control their domain within each or we will end up with conflicts. If yahoo.com resolves to the 'Yahoo' corporate entity in most AIDs, but is controlled by Baidu in one, can they claim it? If not, what about the user confusion that would entail?

Regardless of the answer to this question, I expect in an AID world everyone would start using external domains for the stronger guarantees they provide. So Yahoo would be permanently yahoo.com.A. Which is complicated by...

* 4. Blocking.

If AIPs start blocking resolution of specific external domains, what happens? Obviously China would like this, but for the internet at large, having siloed intranets would likely be a huge problem. Every time someone misconfigures BGP and one region of the internet cannot talk to another, things break. A shifting set of resolvable domains would likely cause exactly the same headaches, only they wouldn't go away with the next BGP update.

* 5. Proxying and scale.

The AIP DNS are required to proxy requests to external domains (3.2 from the draft). Presumably this is to facilitate blocking, but it would also impose significant load issues and key bottlenecks. Note that right now the only equivalent is the root DNS, and it only handles resolution for the TLDs. Something far larger would need to be set up to be able to handle the load of proxying all external requests.

Overall, this proposal has far too many foundational issues to be seriously considered. I am personally happy it was drafted - work to break the One True Root should be done in the open with all relevant parties involved. But this draft isn't going to cut it.

[1] http://en.wikipedia.org/wiki/Alternative_DNS_root [2] http://tools.ietf.org/html/rfc2826 (IAB Technical Comment on the Unique DNS Root)

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#24
post #22

I can barely read it... the spelling and grammar are terrible. This can NOT be a real effort... can it?

Access to people that write good english can be very hard to get in China, so that is probably not a good indicator of anything in this case.

Unless the Great Firewall also blocks websites offering proofreading services, I'm not sure if that's a valid excuse.

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#25
It doesn't make sense to do this just to block sites. They are already doing it.

Can it be a fallout from the SOPA fiasco? Assuming best intentions :)- It seems like running your own autonomous root DNS enables them to stay up even if the domain name is taken down by domain hosts.

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#26
post #4
post #3

It's not an RFC, it's an Internet Draft (which anyone can submit without review), and anyway it's offensive and incoherent enough that nobody will take it seriously, and it certainly won't make it as an actual RFC.

Why is it offensive? How is it incoherent?

It seems to be based more in politics and fear, than any rational thought.

The politics alone would disqualify it.

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#27
post #6

I wonder if this is just because they would like as much control over their population as possible and they want their own Internet, as they would like their own "Twitter", and own "Facebook" and so on, out of a strong sense of nationalism, or because they are worried that US wants more and more control of the Internet, and could be why they are also support getting the Internet under UN's control (among other things…

IMO it's to keep the country together. Super-large nations tend to promote separatist movements along its fringes. In the case of Russia and China they're held together with a strict regime. Other countries provide levels of autonomy on a more granular level. As a rule: monolithic = dictatorial. The moment they get true democracy in China will be the start of armed conflicts and calls for independence along the border regions. Again, just my opinion.

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#28
I'm having trouble understanding what this buys even the Chinese. As far as I can tell, this proposal is the equivalent of all clients putting "search cn" (for example) in their resolv.conf; local "cn" domains will then be searched first, falling back on non-cn domains only if no .cn domain is found. The only difference is that the code to handle this "search cn" directive would be in the DNS server instead of the client.

This doesn't have any "teeth" unless they also blocked non-Chinese DNS servers. But they could do that already, even today. I just don't get why they're coming to the table trying to convince the rest of the Internet to do something, when they seem to already have the tools they need to do this themselves.

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#29

I'm having trouble understanding what this buys even the Chinese. As far as I can tell, this proposal is the equivalent of all clients putting "search cn" (for example) in their resolv.conf; local "cn" domains will then be searched first, falling back on non-cn domains only if no .cn domain is found. The only difference is that the code to handle this "search cn" directive would be in the DNS server instead of the cl…

There is a worldwide political pressure around DNS filtering, redirection and manipulation. [1,2,3] The same pressure is going to come to IP as soon as DNS-poisoning workarounds will spread to more lay people.

Probably China is trying to show the way, even the technical way, on how to apply internet-wide censorship to other "freedom loving" countries. I think China may also be seeking some kind of official recognition of the fact they are not the only bad guys in town, that other countries are implementing the same measures, although with much less bad public reaction. If other countries will reference that Internet Draft in their (leaked) technical manuals or even participate in the discussion of it, China could much more easily justify its actions.

[1] http://m.zdnet.com.au/dns-poisoning-the-thin-end-of-a-wedge-... [2] http://vrritti.com/2012/05/23/dutch-justice-department-wants... [3] http://www.guardian.co.uk/technology/2012/apr/30/british-isp...

Re: Chinese RFC proposes separate, independent, national internets and DNS roots

#30

I can barely read it... the spelling and grammar are terrible. This can NOT be a real effort... can it?

There are a few grammar mistakes sure, but it makes sense to me.

tl;dr:

In order to realize the transition from Internet to Autonomous Internet, each partition of current Internet should first realize possible self-government and gradually reduce its dependence on the foreign domain names, such as COM, NET et al. Then to each AIP network, we can establish a new autonomous DNS, or Upgrade one part of current Internet DNS (core part or non core part) to a new autonomous DNS.

Go right ahead guys, anybody can configure their name resolvers that way if they want to. The part that they're not saying is that in order to force this upon their users they will have to block DNS packets from traversing across their border.

I can't imagine the IETF is going to go for this.

Post reply on HN