3 ms·
This would certainly be huge overhead at the dns server right? I'm curious if anyone manages an authoritative DNS server? I currently manage four rather large
by deaps 8y ago
This would certainly be huge overhead at the dns server right? I'm curious if anyone manages an authoritative DNS server? I currently manage four rather large ones and the collective whole serves up between 400,000 and 900,000 responses per second.
- londons_explore 8y agoPossibly load would in fact go down. Current DNS requests over UDP can (and frequently are) spoofed because there is no way of validating the sender is who they say they are. With DNSoverHTTPS, the sender must be able to receive replies at their IP address, so cannot spoof who they are easily, closing off a lot of avenues for DoS attecks on your and other peoples recursive resolvers.
- jedisct1 8y agoHTTPS is not required to mitigate this. Spoofing the sender IP is only useful to conduct DNS reflection attacks, where a small question is sent, and a much larger response is sent back to the (possibly spoofed source IP). If you require the question to be at least as large as the response, amplification is not a concern any more, so UDP is perfectly fine. This is what the DNSCrypt protocol is doing.
- londons_explore 8y ago1 Million responses per second on a 8 core 2 Ghz mahine means you have 16,000 clock cycles to formulate a response to each query. Considering that [1] claims 1.43 cycles per byte for Chacha20, and assuming requests & responses are typically 200 bytes (they will compress well with HTTP header compression), the actual encryption part of https only consumes 1.43 * 200 = 286 cycles. The remaining 15,716 clock cycles should be plenty to read the actual responses from the cache and parse the HTTP/2 request bytes. Obviously all of the above assumes you design your infrastructure purely for performance. Writing everything in Python and NodeJS might suddenly burn up all those 15,716 clock cycles! [1]: https://eprint.iacr.org/2013/759.pdf https://eprint.iacr.org/2013/759.pdf
- deaps 8y agoI checked the cpu stats - and what you describe is definitely accurate - these boxes spend most of their clock ticks on idle...which is amazing. At 3 Ghz and 8 cores - we're talking 24,000 clock cycles to come up with a response.
- jedisct1 8y agoAbout a factor of 10x increase in packets per second: https://twitter.com/PowerDNS_Bert/status/1064290946731384832 https://twitter.com/PowerDNS_Bert/status/1064290946731384832