3 ms·
Just let google run some of the roots - I'm serious. For all the whining about bandwidth and traffic, this issue is so small on the scale of google (which inclu
by temp667 6y ago
Just let google run some of the roots - I'm serious. For all the whining about bandwidth and traffic, this issue is so small on the scale of google (which includes youtube) and netflix traffic flows it's hard to even imagine.
Their secondary resolvers run at huge volumes, everything from 8.8.8.8 to the dns for their mail and other web properties.
- jeffbee 6y agoThe problem is it does not help to have one or two fast roots. The root server model only really works when the roots each have similar capacity.
- temp667 6y agoA root is not one static machine. Google can serve 1/3 of traffic for all routes, AWS could do the same. I don't think folks realize how SMALL the root dns traffic is. Youtube / netflix / amazon prime video are just orders and orders of magnitude more demanding in terms of bandwidth - every second they are pumping MULTIPLE HD streams to millions of folks. They measure bandwidth terrabits per second. Even at 30 frames per second, we are talking incredible bandwidth. DNS responses should be 1K or less (often .5K). About 40 netflix viewers at their top quality use the same bandwidth? Netflix has far more than 40 users.
- jeffbee 6y agoYou think the root operators should just delegate part of the traffic of all letters' VIPs to google and amazon? It's not crazy, but it would mean the entire root would have a shared-fate failure mode.
- tremon 6y agoI don't understand. What's the failure mode you're thinking of?
- jeffbee 6y agoSomeone at Google pushes yet another invalid config of death, taking out their global network and, with this proposal, also taking down 1/3rd of all DNS root capacity.
- temp667 6y agoYou could easily 3x provision root dns (or more). I'm just pointing out that for all the complaining about google efforts to block domain jacking (which was endemic before they started their efforts) scaling the root is doable, and if the existing maintainers are too incompetent to scale it then maybe others should be allowed to. I mean, how do they handle denial of service attacks which are going to be orders of magnitude higher in volume? The logic here is so warped. https://www.digitalinformationworld.com/2020/08/a-major-bug-in-google-chrome-is-causing-a-massive-load-on-global-root-dns-servers.html https://www.digitalinformationworld.com/2020/08/a-major-bug-... Rather than the solution being to allow for domain hijacking by turning off the redirect detectore, how about verisign, which kicked this whole thing off recently AND way back with their "sitefinder" garbage get a clue and either propose another solution to domain jacking or scale the root a bit.
- DenseComet 6y agoThere already is precedence for this. Cloudflare provides a huge chunk of F-root servers. https://blog.cloudflare.com/f-root/ https://blog.cloudflare.com/f-root/