Live data from Hacker News

Shutting down our public encrypted DNS

mullvad.net

251–260 of 269 posts

Re: Shutting down our public encrypted DNS

#251

Earlier quoted context omitted.

"your code is a trade secret protected via contracts" isn't enough to replace copyright because the contracts are only enforceable to the signing parties. Let's say you write some software for your employer and they sell the product to several customers with a contract not to distribute it. However, the product appears on some pirate website anyway, and you can't identify who allowed the product to be leaked. Once it…

Yeah, I'm assuming most people here aren't selling proprietary code to customers directly. I assume most professionals here work somewhere that sells SaaS or uses the software they develop internally only.

Even if they don't sell the code to the customers directly (or even binaries, because that's what most customers actually care about), somebody in the chain is selling that software to the end customer and that money is going up the chain. It's kind of obvious really - if the work you're doing isn't creating saleable value, then your company won't be able to pay you.

But there is far, far more in the world that just SaaS or internal only software. Sure, companies are generally shifting towards SaaS (in part because it allows them another way to combat piracy, but also to extract recurring revenue rather than one off purchases), but there's still plenty of software you can go out to the shop and buy. Most of that wouldn't exist without copyright laws, because those developers would have found some other way of making a living instead.

Re: Shutting down our public encrypted DNS

#252
post #214

Earlier quoted context omitted.

I don’t honestly see how that’s necessarily better. Now your ISP can tap your individual household to see what’s being queried. Whereas if you use Do[THU] to connect to some remote recursive resolver it practically functions as a mixer.

That’s why I suggested routing queries through a VPN or Tor if that’s a concern. This bypasses centralized DNS services that may face national blocking orders while retaining privacy.

I don't see how that's an improvement over using a big public resolver. Probably worse privacy (you've basically just swapped your ISP for another virtual ISP), and worse performance (likely longer network paths from your resolver to various authoritative servers, as well as not getting the benefits from the nicely-warmed caches that big public resolvers will have).

Re: Shutting down our public encrypted DNS

#253

Earlier quoted context omitted.

Yeah, I'm assuming most people here aren't selling proprietary code to customers directly. I assume most professionals here work somewhere that sells SaaS or uses the software they develop internally only.

Even if they don't sell the code to the customers directly (or even binaries, because that's what most customers actually care about), somebody in the chain is selling that software to the end customer and that money is going up the chain. It's kind of obvious really - if the work you're doing isn't creating saleable value, then your company won't be able to pay you. But there is far, far more in the world that just…

> somebody in the chain is selling that software to the end customer

Not necessarily? Any infra software is invisible to the end consumer. It's bundled into the price the customer pays for what they see, but they themselves don't know or care about the former.

> there's still plenty of software you can go out to the shop and buy

... is there? I haven't bought software in a shop in 20 years at least. Outside of games, I don't really buy software digitally, even. It's either FOSS or it's a subscription.

Re: Shutting down our public encrypted DNS

#254

Earlier quoted context omitted.

Can you elaborate?

Many left ultras (broadly defined, including Trotskyites, leftcoms, and radlibs alike) have somehow adopted the position that only groups who identify with their cultural agenda qualify as “left”, which is frankly a perversion of the left-right descriptor. It’s why the whole left-right thing should be abandoned, as the waters are hopelessly muddied. Somehow you now have “radical” neoliberals (lol) and leftcoms both c…

... isn't that exactly what you're doing?

As for "how is Stalin a rightist", how isn't he? Looking at his Wikipedia bio he seems basically indistinguishable from Hitler, but he called it a different word.

Re: Shutting down our public encrypted DNS

#255

Earlier quoted context omitted.

> CC0 is an explicit attempt to emulate public domain in license form, isn't it? Public domain is something different from an emulation of "there is no copyright": You can take public domain material to build some program binary: - In the current legal system, you can enforce restrictions on the usage of this binary, and can forbid redistribution, reverse-engineering, ... - In a "no copyright world", you cannot enfor…

> In the current legal system, you can enforce restrictions on the usage of this binary [from a public domain source], and can forbid redistribution, reverse-engineering IAAL and am pretty familiar with U.S. copyright law, and am curious where support for this proposition in the law is found. Can you provide sources, please?

I don't know the US law (I live in Germany), but the intuition is clear:

1. Take some CC0/public domain source code.

2. Build a binary out of it and sell licenses for your software.

Case study: SQLite's source code is public domain. On the other hand, it is embedded in many commercial software products that are sold - and you are not allowed to reverse-engineer the software or redistribute binaries of it. This would be possible/allowed in a no-copyright world.

Re: Shutting down our public encrypted DNS

#256
post #224

Earlier quoted context omitted.

> The German courts entirely disregarded our use of geo-IP lookups on queries, and asserted that since tests via a VPN were able to resolve the domain, we were in breach of court orders Seriously, what the fuck? So you're supposed to block VPNs as well? What's next, Tor exit nodes? New VPN and Tor nodes as they pop up? I really don't like where this is going.

In related news, the Spanish soccer league LaLiga successfully won an injunction against Cloudflare so that during Spanish soccer matches ISPs have to prevent access for their users to the entire Cloudflare CDN network. The reason is that the CDN network is/was being used to illegally stream games so access to the entire CDN network is closed. https://apnews.com/article/laliga-cloudflare-piracy-spanish-... https://ha…

There’s a reasonable solution. Banks and vital services that use Cloudflare need to win an injunction that enjoins LaLiga from playing matches.

Re: Shutting down our public encrypted DNS

#257

Earlier quoted context omitted.

> In the current legal system, you can enforce restrictions on the usage of this binary [from a public domain source], and can forbid redistribution, reverse-engineering IAAL and am pretty familiar with U.S. copyright law, and am curious where support for this proposition in the law is found. Can you provide sources, please?

I don't know the US law (I live in Germany), but the intuition is clear: 1. Take some CC0/public domain source code. 2. Build a binary out of it and sell licenses for your software. Case study: SQLite's source code is public domain. On the other hand, it is embedded in many commercial software products that are sold - and you are not allowed to reverse-engineer the software or redistribute binaries of it. This would…

[deleted]

Re: Shutting down our public encrypted DNS

#258

Earlier quoted context omitted.

Many left ultras (broadly defined, including Trotskyites, leftcoms, and radlibs alike) have somehow adopted the position that only groups who identify with their cultural agenda qualify as “left”, which is frankly a perversion of the left-right descriptor. It’s why the whole left-right thing should be abandoned, as the waters are hopelessly muddied. Somehow you now have “radical” neoliberals (lol) and leftcoms both c…

... isn't that exactly what you're doing? As for "how is Stalin a rightist", how isn't he? Looking at his Wikipedia bio he seems basically indistinguishable from Hitler, but he called it a different word.

No, I am falling back on the entire body of left scholarship with the exception of the French Theory school and the non-DSA New Left, who have hijacked the “left” term and refuse to acknowledge its history.

The DSA, an actually serious left-wing group, acknowledges the broad spectrum of left movements and does not attempt to gatekeep. I would say that ultras should learn from them, but ultras are part of a religion, not a political movement—they are not willing to tolerate dissent.

(Also, the poor state of modern leftism is likely a result of well-documented intelligence and law enforcement interference in left movements. Since the 1960s they have been heavily involved in promoting the “cultural” left over the economic left. This would explain the emergence of the with-us-or-against-us tendency among ultras, it’s a great tool to divide and conquer.)

Re: Shutting down our public encrypted DNS

#259
post #252

Earlier quoted context omitted.

That’s why I suggested routing queries through a VPN or Tor if that’s a concern. This bypasses centralized DNS services that may face national blocking orders while retaining privacy.

I don't see how that's an improvement over using a big public resolver. Probably worse privacy (you've basically just swapped your ISP for another virtual ISP), and worse performance (likely longer network paths from your resolver to various authoritative servers, as well as not getting the benefits from the nicely-warmed caches that big public resolvers will have).

A “virtual” ISP may not have my personal details, especially if I am careful about it. I agree that it’s a tradeoff. Some people may live under regimes where big DNS servers are blocked or under legal orders, or they may have concerns about imminent DNS censorship or logging orders.

Re: Shutting down our public encrypted DNS

#260
post #252

Earlier quoted context omitted.

I don't see how that's an improvement over using a big public resolver. Probably worse privacy (you've basically just swapped your ISP for another virtual ISP), and worse performance (likely longer network paths from your resolver to various authoritative servers, as well as not getting the benefits from the nicely-warmed caches that big public resolvers will have).

A “virtual” ISP may not have my personal details, especially if I am careful about it. I agree that it’s a tradeoff. Some people may live under regimes where big DNS servers are blocked or under legal orders, or they may have concerns about imminent DNS censorship or logging orders.

- Personal details isn't the point (and while a VPN service may have those, a big DNS resolver certainly doesn't)--the point is that correlating DNS traffic with your source/home IP address is likely easier with a big DNS resolver. In any case, I don't see how the VPN approach is superior here.

- People may also live under regimes where VPN providers are blocked. Unless there's some order of magnitude more limitations on DNS resolvers, I don't see how the VPN approach is superior here.

Post reply on HN