Live data from Hacker News

In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

indico.dns-oarc.net

31–40 of 73 posts

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#31

Earlier quoted context omitted.

> since Cloudflare is a CIA operation Source for this extraordinary claim?

They were probably exaggerating but it’s well known that American agencies can and will extort whatever they need from any American company and the organisation wouldn’t even be legally allowed to disclose that it even happened through secrecy and gag orders.

“Well known” in conspiracy circles. You’re referring to national security letters and, no, those cannot compel “whatever they need”: it’s limited to release of transactional data, not payload:

https://en.wikipedia.org/wiki/National_security_letter

Part of why the news about MUSCULAR was so shocking was that the Buah-era NSA was attacking the fiber connections between American tech companies’ data centers, because they did NOT have a legal way to get that level of information.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#32

It is shocking how few people understand how DNS works

Given this isn’t only DNS, agreed. This changes: - Registry, - Name Server and - DNSEC More details here: https://indico.dns-oarc.net/event/48/contributions/1038/atta...

Those are all part of the DNS.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#33
post #26

It is shocking how few people understand how DNS works

It is shocking how few people understand how business works. If you think Cloudflare wants to be in the registrar business, not push their Anti DDoS stuff on a captive audience, I have a bridge to sell you.

> push their Anti DDoS stuff on a captive audience

This is a very provocative way to spin “selling the CDN services customers are buying”. What reason do we have to think anyone is an unwilling party to that transaction?

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#34
post #7

Does this mean every GOV page will now have the "pretend security check" interstitial that litter just about every page now? How do you even describe it, it's like they are vandalising the internet.

You're getting downvoted, but I guess none of the downvoters tried to apply recently on https://esta.cbp.dhs.gov/esta/ , I'm getting the infinite turnstile cloudflare hcaptchas. It's probably happening to most people trying to use that website from 3rd world countries.

He’s getting downvoted for confusing two unrelated services. What you’re both talking about is what happens when someone uses Cloudflare’s CDN, enables their managed CAPTCHA feature, and directs their web traffic through it. This is about DNS, which is a separate service at a lower level.

Agencies would have to contract with Cloudflare separately to use the CDN, and each contract is a separate competition where a different part of the government using Cloudflare for a different service would not be considered when reviewing bids.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#35
post #26

It is shocking how few people understand how DNS works

It is shocking how few people understand how business works. If you think Cloudflare wants to be in the registrar business, not push their Anti DDoS stuff on a captive audience, I have a bridge to sell you.

> registrar business

They're the registry, not the registrar. CISA is the registrar for .gov domains, Cloudflare just handles the backend. (DNS and whois infrastructure)

Government employees likely never see anything about Cloudflare at all when they manage the DNS settings for domains, just like I never see anything about Charleston Road Registry (Google subsidiary) when I manage a .dev domain on Name.com.

> push their Anti DDoS stuff on a captive audience

How is this a captive audience? Are you implying Cloudflare won't allow .gov domains to use non-cloudflare nameservers?

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#37

It is shocking how few people understand how DNS works

It never fails to amuse. Our world is full of really complex tech which people are eager to learn, yet those same people will seem to be allergic to DNS despite it being very simple (at least the main parts of it).

Look at the amount of coders who can struggle with simple system settings.

Some people only learn what they want to or need to learn, the bare minimum.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#38

Earlier quoted context omitted.

They've just taken over authorative DNS. The captchas come from their CDN product.

You can't use https://esta.cbp.dhs.gov/esta/ from my country without an infinity of hcaptchas by CF turnstile.

A particular .gov domain using Cloudflare (although from my DNS lookups, that one is not) is unrelated to Cloudflare managing the authoritative DNS servers for the .gov TLD. The fact that only a specific .gov domain - not all of them - has this issue demonstrates that.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#39

Earlier quoted context omitted.

They've just taken over authorative DNS. The captchas come from their CDN product.

You can't use https://esta.cbp.dhs.gov/esta/ from my country without an infinity of hcaptchas by CF turnstile.

Are you sure about that?

esta.cbp.dhs.gov seems to served by akamai at least for me.

Also turnstile and hcaptchas are same product(captcha) by 2 different companies.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#40

There's a very interesting document by Cloudflare linked to it that describes why this was not your typical "change nameserver and done" transition: https://indico.dns-oarc.net/event/48/contributions/1038/atta...

yet another example of DNSSEC "adding value"
Post reply on HN