5 ms·
So much to respond to here. I am one of those companies running a recursive DNS service, DNSFilter.com We are not advertising driven. OpenDNS cut the ads a fe
by LogicX 10y ago
So much to respond to here.
I am one of those companies running a recursive DNS service, DNSFilter.com
We are not advertising driven. OpenDNS cut the ads a few years ago.
We do not run open resolvers, we just have paying customers who wish to use our service.
The DNS extensions you are referring to are the EDNS0 Client Subnet extension. It is in wide use by authoritative servers for major CDNs and is supported by a number of recursive DNS providers. See the spec here: https://tools.ietf.org/html/draft-ietf-dnsop-edns-client-subnet-08 https://tools.ietf.org/html/draft-ietf-dnsop-edns-client-sub... Section 11 addresses your concerns about IP addresses being shared: It is encouraged to provide only as much granularity as is necessary based on network architecture. At no time is there a reason to share the last octect of an address (since Internet BGP routing is limited to a /24)
We do not run an authoritative DNS service, yet are working to improve encrypted communications... in coordination with industry authoritative partners. Very early stages, but we are driven to protect our customers and the Internet at large. Every time I hear someone misunderstanding what DNSSEC is, and why they think they want it, I'm encouraged to work on solutions such as dnscrypt or DNS over TLS: https://tools.ietf.org/html/rfc7858 https://tools.ietf.org/html/rfc7858
- geocar 10y agoHi there, I work in advertising, and I absolutely use the EDNS0 data to track users. I'm okay with a 1:250ish potential error rate since outside of facebook and google, you probably don't go to the same websites as your neighbour. Thanks for your hard work.
- chillydawg 10y agoHow does that work?
- geocar 10y agoI log the requests to my DNS servers. My client embeds information I need into the host part and the custom DNS server always returns NXDOMAIN.
- pfg 10y agoI'm curious: what's the reason for doing this rather than just logging the IP addresses that hit your server directly? Is this a way to get around VPNs that leak the real IP via DNS? Or does this allow you to get something back from users with ad blockers that block the request, but no the DNS lookup (I don't know if this is the case)? Is it just a performance optimization (just a DNS lookup vs. a HTTP request)?
- geocar 10y agoI don't have a server for them to hit directly: My DNS server always returns NXDOMAIN.
- sGatling1788 10y agoHow was OpenDNS able to cut the ads yet provide free service?
- tresni 10y agoFull Disclosure - work for Cisco/OpenDNS. https://www.opendns.com/no-more-ads/ https://www.opendns.com/no-more-ads/ talks about why we shut off ads. As to "how" we were able to. We do offer paid services to both home and business (SMB through Enterprise) users. Additionally, we are a security and data company -- free service feeds into data driven models for security that benefits all suers.
- GTP 10y agoFrom section 11 of the draft: "To protect users' privacy, Recursive Resolvers are strongly encouraged to conceal part of the IP address of the user by truncating IPv4 addresses to 24 bits. 56 bits are recommended for IPv6, based on [RFC6177]. ISPs should have more detailed knowledge of their own networks. That is, they might know that all 24-bit prefixes in a /20 are in the same area. In those cases, for optimal cache utilization and improved privacy, the ISP's Recursive Resolver SHOULD truncate IP addresses in this /20 to just 20 bits, instead of 24 as recommended above. Users who wish their full IP address to be hidden need to configure their client software, if possible, to include an ECS option specifying the wildcard address (i.e. SOURCE PREFIX-LENGTH of 0). As described in previous sections, this option will be forwarded across all the Recursive Resolvers supporting ECS, which MUST NOT modify it to include the network address of the client". So it's suggested that DNS providers and ISPs use only a portion of the IP address but they aren't forced to do so (and how could they be forced anyway?). Then it says that users that don't want to send their IP address should configure their software accordingly, but again only "if possible" so again no guarantee that it would be possible. Now a question: I don't see why a DNS packet would contain the client's IP address and a (I admit too quick) look at the draft didn't provided any information. Could you please elaborate on the supposed advantages of this practice?
- MichaelGG 10y agoIt's to return local DNS records so you resolve to a nearby server.
- GTP 10y agoI have one more question. DNS requests are carried by the IP protocol, so when someone makes a DNS interrogation the DNS server already gets the client's full IP address in the IP header. Isn't redundant to place (a portion of) the IP address in a DNS packet? Or maybe for some reason the DNS server is quicker to get this information from the DNS packet rather than from the IP packet's header?
- MichaelGG 10y ago