5 ms·
A root is not one static machine. Google can serve 1/3 of traffic for all routes, AWS could do the same. I don't think folks realize how SMALL the root dns tra
by temp667 6y ago
A root is not one static machine. Google can serve 1/3 of traffic for all routes, AWS could do the same.
I don't think folks realize how SMALL the root dns traffic is. Youtube / netflix / amazon prime video are just orders and orders of magnitude more demanding in terms of bandwidth - every second they are pumping MULTIPLE HD streams to millions of folks. They measure bandwidth terrabits per second. Even at 30 frames per second, we are talking incredible bandwidth.
DNS responses should be 1K or less (often .5K). About 40 netflix viewers at their top quality use the same bandwidth? Netflix has far more than 40 users.
- jeffbee 6y agoYou think the root operators should just delegate part of the traffic of all letters' VIPs to google and amazon? It's not crazy, but it would mean the entire root would have a shared-fate failure mode.
- tremon 6y agoI don't understand. What's the failure mode you're thinking of?
- jeffbee 6y agoSomeone at Google pushes yet another invalid config of death, taking out their global network and, with this proposal, also taking down 1/3rd of all DNS root capacity.
- temp667 6y agoYou could easily 3x provision root dns (or more). I'm just pointing out that for all the complaining about google efforts to block domain jacking (which was endemic before they started their efforts) scaling the root is doable, and if the existing maintainers are too incompetent to scale it then maybe others should be allowed to. I mean, how do they handle denial of service attacks which are going to be orders of magnitude higher in volume? The logic here is so warped. https://www.digitalinformationworld.com/2020/08/a-major-bug-in-google-chrome-is-causing-a-massive-load-on-global-root-dns-servers.html https://www.digitalinformationworld.com/2020/08/a-major-bug-... Rather than the solution being to allow for domain hijacking by turning off the redirect detectore, how about verisign, which kicked this whole thing off recently AND way back with their "sitefinder" garbage get a clue and either propose another solution to domain jacking or scale the root a bit.
- DenseComet 6y agoThere already is precedence for this. Cloudflare provides a huge chunk of F-root servers. https://blog.cloudflare.com/f-root/ https://blog.cloudflare.com/f-root/