8 ms·
I prefer http://curvedns.on2it.net http://curvedns.on2it.net This was the original. Other than having to modify their ksh script, it is painless to set up. I
by gwu78 10y ago
I prefer http://curvedns.on2it.net http://curvedns.on2it.net
This was the original.
Other than having to modify their ksh script, it is painless to set up.
In my opinion, authoritative nameservers, and therefore DNSCurve forwarders like CurveDNS, are more important than recursive resolvers/caches such as OpenDNS and DNSCrypt.
A recursive resolver should be authoritative for nothing. They are middlemen. Companies that offered this "service", such as OpenDNS, had to pander to advertisers, or were run by advertising companies themselves, e.g., Google.
The "rules" of DNS are easily broken. This applies to caches. One does not need to look very far to find resolvers that someone has designated as "authoritative". dnsq: "weird ra". This often means an open resolver IME.
A while back some companies including the ones named above if I am not mistaken were pushing for extensions in DNS to put at least part of user IP addresses into DNS packets so cache operators could track them. The reason? Advertising. (Although maybe they would cite other reasons.) Not sure what ever happened with that. BIND had started to implement it. Thankfully djbdns will never support this garbage.
This kind of nonsense is why I cannot get excited about the latest extensions to internet protocols anymore.
Too often they are for the benefit of web companies and advertisers, not users.
The "encrypted DNS revolution", if it ever comes, is not going to be initiated by companies running recursive resolvers. (Unless they also run authoritative nameservers.)
Note: When the user runs their own cache on localhost there is no need to determine nearest POP.
- papaf 10y agoIt quite easy to setup DNSCrypt with OpenNIC[1] and then a lot of the downsides that you mention go away. Here is some background and setup instructions: https://markbrown778.wordpress.com/2014/08/08/dns-privacy-using-opennic-and-dnscrypt/ https://markbrown778.wordpress.com/2014/08/08/dns-privacy-us... [1] https://www.opennicproject.org/ https://www.opennicproject.org/
- MertsA 10y ago>The reason? Advertising. Or the ability to accurately direct users to the nearest POP.
- bluejekyll 10y agoYes, for people who don't know, this is how many things like directing users to a closer TLS endpoint for HTTP such that the overall connection suffers less latency.
- fidget 10y agoIsn't anycast ip usually used for that instead?
- bluejekyll 10y agoIt entirely depends, anycast is great for getting a request to the closest DNS endpoint via routing weight rules. After that, there are many options. But the GP was specifically mentioning a valid use case where this is applicable and not shady.
- LogicX 10y agoSo much to respond to here. I am one of those companies running a recursive DNS service, DNSFilter.com We are not advertising driven. OpenDNS cut the ads a few years ago. We do not run open resolvers, we just have paying customers who wish to use our service. The DNS extensions you are referring to are the EDNS0 Client Subnet extension. It is in wide use by authoritative servers for major CDNs and is supported by a number of recursive DNS providers. See the spec here: https://tools.ietf.org/html/draft-ietf-dnsop-edns-client-subnet-08 https://tools.ietf.org/html/draft-ietf-dnsop-edns-client-sub... Section 11 addresses your concerns about IP addresses being shared: It is encouraged to provide only as much granularity as is necessary based on network architecture. At no time is there a reason to share the last octect of an address (since Internet BGP routing is limited to a /24) We do not run an authoritative DNS service, yet are working to improve encrypted communications... in coordination with industry authoritative partners. Very early stages, but we are driven to protect our customers and the Internet at large. Every time I hear someone misunderstanding what DNSSEC is, and why they think they want it, I'm encouraged to work on solutions such as dnscrypt or DNS over TLS: https://tools.ietf.org/html/rfc7858 https://tools.ietf.org/html/rfc7858
- geocar 10y agoHi there, I work in advertising, and I absolutely use the EDNS0 data to track users. I'm okay with a 1:250ish potential error rate since outside of facebook and google, you probably don't go to the same websites as your neighbour. Thanks for your hard work.
- chillydawg 10y agoHow does that work?
- geocar 10y agoI log the requests to my DNS servers. My client embeds information I need into the host part and the custom DNS server always returns NXDOMAIN.
- pfg 10y ago
- xorcist 10y agoI am skeptical to its architecture. This is 2017 and there are compelling reasons for endpoints to do resolving on their own. To get rid of open resolvers would be nice. "But .. caching", well, the performance of resolvers is perhaps not as clear cut as that. Performance would suffer for some, but they can clearly handle it, and does it really matter? Some real world testing would surely be beneficial. In the mean time, I'm not sure about solutions to the resolver data leak problem. It is a solution to a problem we should not have.