Live data from Hacker News

In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

indico.dns-oarc.net

41–50 of 73 posts

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#41

It is shocking how few people understand how DNS works

In people’s defense DNS is complicated. Try building a product that uses it and realize there are a ton of edge cases to handle

Yeah, but it's not like those comments are making a mistake about how the tech works because they're looking to learn something today. Posting an axe-grinding comment that shows a clear misunderstanding of the technology on a technical forum is an unforced and pretty indefensible error.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#42
post #40

There's a very interesting document by Cloudflare linked to it that describes why this was not your typical "change nameserver and done" transition: https://indico.dns-oarc.net/event/48/contributions/1038/atta...

yet another example of DNSSEC "adding value"

By making it hard just to hijack a crucial TLD and transfer it over to an potential adversary without the cooperation of multiple trusted parties? It seems to me this is DNSSEC working as designed, and being remarkably flexible in doing so. Sometimes things _should_ be difficult to do.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#44
post #39

Earlier quoted context omitted.

You can't use https://esta.cbp.dhs.gov/esta/ from my country without an infinity of hcaptchas by CF turnstile.

Are you sure about that? esta.cbp.dhs.gov seems to served by akamai at least for me. Also turnstile and hcaptchas are same product(captcha) by 2 different companies.

Here’s what it looks like from India:

https://www.webpagetest.org/result/240210_BiDcTM_7TZ/

That’s definitely an Akamai IP. I’d be quite surprised if they were leading address space to a direct competitor.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#45
post #25

Earlier quoted context omitted.

> since Cloudflare is a CIA operation Source for this extraordinary claim?

[flagged]

Sorry, but ‘there was a lot of info about it, trust me’ is not really credible.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#46
post #4

I can only imagine conspiracy theories flying around about government partnership with Cloudflare.

There doesn’t need to be any conspiracy theories when governments will often use their leveraged positions to get something from companies and punish them severely if they don't comply. If I remember correctly, there was a certain LEA which approached an US ISP for an informal surveillance request, they refused, and the LEA retaliated by cancelling their contract. I’m failing to find it, so I’d be happy if someone ca…

That sounds vaguely like Qwest.

https://en.wikipedia.org/wiki/Qwest#Refusal_of_NSA_surveilla...

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#47

It is shocking how few people understand how DNS works

Paul Vixie quote and link to explanations: "DNS is a distributed, coherent, reliable, autonomous, hierarchical database, the first and only one of its kind."

https://queue.acm.org/detail.cfm?id=1242499

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#48

It is shocking how few people understand how DNS works

This being the top comment means there are enough people here smug because they know how DNS works. People who need to know generally know. Nobody can know everything and most people don't need to know how it works.

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#49
I didn't even know .gov changed operators until this news, but looks like there was an earlier news that said it would happen:

https://news.ycombinator.com/item?id=34403055 - Verisign Loses Prestige .Gov Contract to Cloudflare (2023-01-16)

Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare

#50
post #46

Earlier quoted context omitted.

There doesn’t need to be any conspiracy theories when governments will often use their leveraged positions to get something from companies and punish them severely if they don't comply. If I remember correctly, there was a certain LEA which approached an US ISP for an informal surveillance request, they refused, and the LEA retaliated by cancelling their contract. I’m failing to find it, so I’d be happy if someone ca…

That sounds vaguely like Qwest. https://en.wikipedia.org/wiki/Qwest#Refusal_of_NSA_surveilla...

Yes, that's the one. Thanks!
Post reply on HN