Live data from Hacker News

Measuring open DNS resolver use

blog.apnic.net

21–30 of 53 posts

Re: Measuring open DNS resolver use

#21
post #17

What this data shows is that concerns about centralization, especially in relation to DoH, are overblown. Only 1.15% of users in this dataset are using Cloudflare DNS, and APNIC is in a region riddled with government censorship and crappy ISPs -- two major incentives for people to try alternative resolvers. Without such incentives, nobody would even bother to change their devices' DNS settings. I'm in a country with…

Agree that shifting control from your state and ISP are beneficial, but centralizing DNS to one or two for-profit providers in the process is less than ideal IMO. I'm working on a project that's aiming to make DNS fully decentralized and wrote an explainer article in case you're interested https://www.namebase.io/blog/meet-handshake-decentralizing-d...

If it's not too revealing, can you share what country you're in?

Re: Measuring open DNS resolver use

#22
post #5
post #2

The argument is well known: the intertubes promises much equanimity but capitalism and stuff. OK I am being a bit cruel but this is what we have. If you don't own up to intending to cuddle up to Amazon, Google, Apple, Microsoft in the next 30s then you are probably a liar or a bit deluded. Thing is, I'm a bit of a fan of capitalism but perhaps some sort of light touch regulation is needed in the Wild West. A bloke wi…

It's probably even worse than what you describe. You'll be cuddling up to the Amazon, Google, Apple, Microsoft of whichever global power you're closest to. I'm in Australia, so I don't know if in twenty years I'll still be connected to Westnet or Sinonet. I'll probably buy a black market connection to Westnet from a guy with a mohawk and implants in his head.

Agreed. The world is trending towards an internet that's split up between the different countries. There are some technologies that can counter that (ie check my bio) but it'll be an uphill battle imo.

Re: Measuring open DNS resolver use

#23
post #8

Folks here might be interested in my own (more tl;dr) survey of public resolver usage: https://twitter.com/mikedamm/status/1136409254305263616?s=20

Do you know how Cloudflare picked up so much market share even with 8.8.8.8 around?

Google doesn’t promote 8.8.x.x lately, so when there were some sites being blocked by Indian ISPs, I saw cloudflare DNS being recommended. Also I believe cloudflare doesn’t implement ban-lists provided by Indian courts. I have noticed sites blocked in google dns, working with cloudflare dns.

Re: Measuring open DNS resolver use

#24

Earlier quoted context omitted.

What is the cause for concern? I am trying to understand why DNS-over-HTTPS could be a bad thing from the user end.

It makes it very hard to control your network. I have a DNS setup at home that I want all my equipment using. It blocks ads and other sites I don't want accessed. With DoH, I can't really be sure that browsers, devices, etc aren't using an alternative DNS system.

You could null route or firewall all the open resolvers, or at least the most common ones.

If your router is linux, that might look like

    /sbin/ip route add blackhole 9.9.9.9 2>/dev/null
    /sbin/ip route add blackhole 1.1.1.1 2>/dev/null
    /sbin/ip route add blackhole 1.0.0.1 2>/dev/null
    /sbin/ip route add blackhole 8.8.8.8 2>/dev/null
    /sbin/ip route add blackhole 8.8.4.4 2>/dev/null
I'm probably leaving many of them off. There is probably a RBL for those by now. Here is one [1] and here is a list of them. [2]

[1] - https://github.com/bambenek/block-doh

[2] - https://github.com/curl/curl/wiki/DNS-over-HTTPS

Re: Measuring open DNS resolver use

#25
I've worked on software that attempts to estimate the end-user demand represented by a given resolver. Most of the specifics are covered by NDA, but suffice to say that it's surprisingly difficult to do accurately. There is a lot of non-standard behavior in various resolver software, some of it avoidable, some of it not.

This trick of altering the hostname of a subresource to identify the client is a thing I long wished we could do, but sadly we didn't have enough control of the content to do that.

Re: Measuring open DNS resolver use

#26
post #23

Earlier quoted context omitted.

Do you know how Cloudflare picked up so much market share even with 8.8.8.8 around?

Google doesn’t promote 8.8.x.x lately, so when there were some sites being blocked by Indian ISPs, I saw cloudflare DNS being recommended. Also I believe cloudflare doesn’t implement ban-lists provided by Indian courts. I have noticed sites blocked in google dns, working with cloudflare dns.

To extend this, I’ve never seen google promote 8.8 publicly. All recommendations I’ve seen have been from other users or forum members. It maybe that Google’s trust isn’t what it once was, causing a reduction in recommendation.

Re: Measuring open DNS resolver use

#27
post #10

Earlier quoted context omitted.

Paul Vixie has been one of the Internet's most dedicated proponents of DNSSEC, a technology that essentially escrows keys with governments. If DNSSEC and DANE had progressed according to Vixie's preferred schedule, Muammar Gaddafi would have owned BIT.LY's CA. Vixie operates a company that relies on passive DNS observation to generate telemetry for corporations. Smart dude. Would not weight his privacy opinions heavi…

DNSSEC doesn't "essentially escrow keys with governments". It's exactly as true to say that DANE gave Gaddafi ownership of bit.ly's CA as to say that today Boris Johnson owns the CA for slither.io - and as ridiculous. Back when you first started claiming this the Ten Blessed Methods weren't even a thing. You're complaining about the inadequate back door lock on a house that has the front door propped open. I work for…

You haven't offered a rebuttal other than saying this argument is "ridiculous". I'm obviously not coming out of nowhere with it. Can you do better than "nuh-uh"?

Re: Measuring open DNS resolver use

#28
post #17

What this data shows is that concerns about centralization, especially in relation to DoH, are overblown. Only 1.15% of users in this dataset are using Cloudflare DNS, and APNIC is in a region riddled with government censorship and crappy ISPs -- two major incentives for people to try alternative resolvers. Without such incentives, nobody would even bother to change their devices' DNS settings. I'm in a country with…

Agree that shifting control from your state and ISP are beneficial, but centralizing DNS to one or two for-profit providers in the process is less than ideal IMO. I'm working on a project that's aiming to make DNS fully decentralized and wrote an explainer article in case you're interested https://www.namebase.io/blog/meet-handshake-decentralizing-d... If it's not too revealing, can you share what country you're in?

Sure, even more decentralization would be good. Nevertheless, I think the usual concerns about Cloudflare are massively overblown and misses a crucial role that they're playing in the fight against censorship and surveillance.

Cloudflare is the first well-known provider that decided to support a working protocol for encrypted DNS. DoH might not be the best possible protocol, but it's shipping now and others are not. (DNSCrypt is also shipping, but it has the weird property of speaking something that isn't HTTPS on port 443. That's too easy to censor.) There will be healthy competition if other people would please stop arguing and start shipping, too.

I'm in South Korea. The censorship regime here is more prudish than draconian, and I'm not in any danger of prosecution for criticizing it. The way it is implemented is extremely crappy, though. On top of DNS-based censorship, ISPs are doing DPI on TLS handshakes to sniff hostnames in the SNI extension. Lots of techies here are very interested in new technologies showcased by Cloudflare. That includes not only DoH but also their proposal to use keys stored in DNS to close the SNI loophole. Once again, what works in this situation is not a novel, theoretically perfect protocol but one that ships now and blends into the petabytes of HTTPS traffic that Cloudflare handles every day.

Re: Measuring open DNS resolver use

#29
post #7
post #6

Earlier quoted context omitted.

It's not. It's an unalloyed good thing. The concern is with configurations that make it hard to use anything but Cloud Flare. There are alternatives.

What do you think about Paul Vixie's views on DoH? On the face of it, it seems like we're going to end up with a bunch of black box devices (from Google, Amazon etc) in our homes that are totally immune to most forms of network policing because between DoH, ESNI, TLS and CDN fronting, you can't see anything .

Will there be any alternatives to those black box devices from Google, Amazon, etc.?

Re: Measuring open DNS resolver use

#30
post #10
post #7

Earlier quoted context omitted.

What do you think about Paul Vixie's views on DoH? On the face of it, it seems like we're going to end up with a bunch of black box devices (from Google, Amazon etc) in our homes that are totally immune to most forms of network policing because between DoH, ESNI, TLS and CDN fronting, you can't see anything .

Paul Vixie has been one of the Internet's most dedicated proponents of DNSSEC, a technology that essentially escrows keys with governments. If DNSSEC and DANE had progressed according to Vixie's preferred schedule, Muammar Gaddafi would have owned BIT.LY's CA. Vixie operates a company that relies on passive DNS observation to generate telemetry for corporations. Smart dude. Would not weight his privacy opinions heavi…

my impression from his latest talk at eurobsdcon this weekend was that he promotes dns over tls first and foremost. you can see for yourself when the videos go up.
Post reply on HN