Live data from Hacker News

Measuring open DNS resolver use

blog.apnic.net

1–10 of 53 posts

Re: Measuring open DNS resolver use

#2
The argument is well known: the intertubes promises much equanimity but capitalism and stuff.

OK I am being a bit cruel but this is what we have. If you don't own up to intending to cuddle up to Amazon, Google, Apple, Microsoft in the next 30s then you are probably a liar or a bit deluded.

Thing is, I'm a bit of a fan of capitalism but perhaps some sort of light touch regulation is needed in the Wild West. A bloke with a big old star on the chest might be nice.

Re: Measuring open DNS resolver use

#5
post #2

The argument is well known: the intertubes promises much equanimity but capitalism and stuff. OK I am being a bit cruel but this is what we have. If you don't own up to intending to cuddle up to Amazon, Google, Apple, Microsoft in the next 30s then you are probably a liar or a bit deluded. Thing is, I'm a bit of a fan of capitalism but perhaps some sort of light touch regulation is needed in the Wild West. A bloke wi…

It's probably even worse than what you describe. You'll be cuddling up to the Amazon, Google, Apple, Microsoft of whichever global power you're closest to.

I'm in Australia, so I don't know if in twenty years I'll still be connected to Westnet or Sinonet. I'll probably buy a black market connection to Westnet from a guy with a mohawk and implants in his head.

Re: Measuring open DNS resolver use

#6

I think DNS-over-HTTPS is a much bigger cause for concern.

What is the cause for concern? I am trying to understand why DNS-over-HTTPS could be a bad thing from the user end.

It's not. It's an unalloyed good thing. The concern is with configurations that make it hard to use anything but Cloud Flare. There are alternatives.

Re: Measuring open DNS resolver use

#7
post #6

Earlier quoted context omitted.

What is the cause for concern? I am trying to understand why DNS-over-HTTPS could be a bad thing from the user end.

It's not. It's an unalloyed good thing. The concern is with configurations that make it hard to use anything but Cloud Flare. There are alternatives.

What do you think about Paul Vixie's views on DoH?

On the face of it, it seems like we're going to end up with a bunch of black box devices (from Google, Amazon etc) in our homes that are totally immune to most forms of network policing because between DoH, ESNI, TLS and CDN fronting, you can't see anything.

Re: Measuring open DNS resolver use

#9
post #6

Earlier quoted context omitted.

What is the cause for concern? I am trying to understand why DNS-over-HTTPS could be a bad thing from the user end.

It's not. It's an unalloyed good thing. The concern is with configurations that make it hard to use anything but Cloud Flare. There are alternatives.

From a security and privacy standpoint I think DoH is a good thing.

I wish it didn't have the overhead of TCP/HTTP (which is why I was a bigger fan of DNSCrypt). Anyone can stand up a resolver that can handle 50k UDP requests a second and operate a public resolver. It starts to get operationally dicey to stand up infrastructure that can do 50k HTTP requests a second. As a result you end up with a small handful of players who can operate medium to large scale public resolvers.

Re: Measuring open DNS resolver use

#10
post #7
post #6

Earlier quoted context omitted.

It's not. It's an unalloyed good thing. The concern is with configurations that make it hard to use anything but Cloud Flare. There are alternatives.

What do you think about Paul Vixie's views on DoH? On the face of it, it seems like we're going to end up with a bunch of black box devices (from Google, Amazon etc) in our homes that are totally immune to most forms of network policing because between DoH, ESNI, TLS and CDN fronting, you can't see anything .

Paul Vixie has been one of the Internet's most dedicated proponents of DNSSEC, a technology that essentially escrows keys with governments. If DNSSEC and DANE had progressed according to Vixie's preferred schedule, Muammar Gaddafi would have owned BIT.LY's CA. Vixie operates a company that relies on passive DNS observation to generate telemetry for corporations. Smart dude. Would not weight his privacy opinions heavily.
Post reply on HN