7 ms·
Why updating DNS is slow
- LogicX 6y agoNot too bad! Covers the major things most forget when trying to understand this question.
- toast0 6y agoWould be nice if they didn't stomp on real addresses. > The blocks 192.0.2.0/24 (TEST-NET-1), 198.51.100.0/24 (TEST-NET-2), and 203.0.113.0/24 (TEST-NET-3) are provided for use in documentation. -- RFC5737 https://tools.ietf.org/html/rfc5737 https://tools.ietf.org/html/rfc5737
- happytoexplain 6y agoOn the other hand, there's something to be said for not using real identifiers in examples.
- deleted 6y ago[deleted]
- rubatuga 6y agoJust wondering, how can a network block have a "2" in "192.0.2.0/24"? Shouldn't it be "192.0.0.0/24"?
- Tushon 6y ago/24 is a 256 host subnet, so you can have 1-254 (0 and 255 are special) in the last "octet" (each section of an IP address is denoted as an octet). You can play with the numbers here [0] to see valid combos, like this: 192.1.254.19/24 (or use a 255.255.255.0 subnet mask) 0 - https://www.calculator.net/ip-subnet-calculator.html?cclass=any&csubnet=24&cip=192.1.254.54&ctype=ipv4&printit=0&x=72&y=17 https://www.calculator.net/ip-subnet-calculator.html?cclass=...
- jlgaddis 6y agoNo, 192.0.0.0/24 and 192.0.2.0/24 are completely separate networks. See "Classless Inter-Domain Routing" [0] (a.k.a. "CIDR") -- [0]: https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing
- Craighead 6y ago/24 means that the first 24 bits are the subnetwork mask, ie: xxxxxxxx.xxxxxxxx.xxxxxxxx.NNN, where the x represent the network and the N represent hosts on said network. 192.168.1.x/24 and 192.168.2.x/24 are two separate networks.
- bnjms 6y agoThere are two types of useful documentation or training materials. 1. The detailed and accurate type which covers everything you need to know and takes time to work through and gather the parts you need to learn. 2. High level gists which share only the basics you need to gather the intuition for the space. This type helps make learning from the first type easier. These comics are the second type. I ran through the questions for TLS and found them helpful. I had so many questions a few months ago and these types of resources are so good for getting you to asking the right questions.
- nreece 6y agoAs as aside, I recently goofed up our company website DNS (updated a record on long TTL with an incorrect), but quickly fixed it and found a partial workaround to propagation: flush the DNS cache of Google[1] and Cloudflare[2]. It helped with DNS cache refresh within minutes from most global locations, if not all. [1] https://dns.google/cache https://dns.google/cache [2] https://1.1.1.1/purge-cache/ https://1.1.1.1/purge-cache/
- saagarjha 6y agoI find it interesting that you can do this for any website at all…
- pathseeker 6y agoIt only costs them a single lookup
- axaxs 6y agoIt's not an attack surface. You're posting relatively tons of data to ask them to do one small lookup.
- bombcar 6y agoIt could be one aspect of a cache poisoning attack. One of the things DNSSEC was to protect against.
- abhishekjha 6y agoI just did it for fb.com. What impact does this have on such huge websites?
- judge2020 6y agoThe cache probably gets re-filled again pretty quickly, if you were to spam this endpoint it'd be more of a problem but I would assume/hope there's rate limiting on it.
- 6y ago
- DomenicoMazza 6y agoHmm.. now I realise that 'live' in 'time to live' is 'live' as in 'life', not 'live' in the 'going live' sense ... It's the record's cache time! Engineering/techy acronyms are a bad place for homographs...
- redis_mlc 6y agoThat's the first time I've heard of that mixup. "Time to go live" is more along your meaning. ETA is more common for what you mentioned, but even that is more for transportation.
- mgmgmgmgmg 6y agoI've had this discussion with multiple colleagues. I say it live as in life. However, most people I know say live as in "until the new record is live"
- hkt 6y agoIs homograph a synonym of homophone or homonym?
- parasquid 6y agotechnically neither; homographs are two words written the same way but with different meaning. homophones are two words that sound the same but written differently. homonyms are somewhat a combination: written and sound the same, but have different meaning. since synonym means "having the same meaning" you might get away with considering a homograph a synonym of homonym, but it's best to be precise in these cases.
- roelschroeven 6y agoI've always thought of it as 'live' as in 'life', but I learned about TTL first in the context of IP packets where the meaning is probably less ambiguous.
- anonymousiam 6y agoOnce you do a (planned) migration of a few sites, you quickly learn to set the DNS TTL to something small beforehand. Alternatively (if possible), keep both IP blocks active for the TTL duration.
- Daho0n 6y agoMany (most?) last hop DNS resolvers (ISP) set their own cache time, sadly.
- comfydragon 6y agoNot to mention some IOT devices or cellular routers/devices might force a longer minimum cache TTL, to "minimize data usage". I worked on a device that did so (minimum pdnsd cache time of 25 hours). It ended up causing failures when our cloud server did a cut-over, dropping the TTLs 24 hours in advance. :(
- QuadrupleA 6y agoI wonder how relevant "long" TTLs (5min, 30min, etc.) still are in an age of massive multi-gigabit fiber links? DNS was invented long ago, a very simple protocol with a handful of bytes per packet - a trickle amid the torrent. Waiting an hour or more for a 4-byte change (an IPv4 address) to be committed to a distributed database seems incredibly antiquated.
- bombcar 6y agoIt's arguably even MORE important in the age of fast links - because now a great percentage of the clock time is spent on handshakes and other "overhead" - so saving a round trip or three on a DNS lookup is comparatively larger than it used to be.
- dijit 6y agoArgh, I hate this kind of question, it overtly implies that because we have more of something (computing resources, memory, networking bandwidth) we should fill the void with something "better", where "better" means different things to different people. DNS doesn't really work this way anyway, you have a tree-like structure and if you're a good little resolver you don't just talk to your upstream DNS server, you walk the path from the root to the stem. I.E; you don't ask your ISPs resolver for server-a.www.google.com you ask the DNS root (".") for who owns com, then you ask "com" who owns google, and you keep going down the NS records you're on the stem, then you ask for an A or a CNAME record.. Then you cache that result _because it's expensive to do that lookup_- and often (ESPECIALLY) on the internet a webpage will ask you to download a dozen more things from the same domain, so a cache makes absolute sense. But, regardless of how expensive DNS is; you miss a _huge_ point about the tech that came before: it's foundational and fundamental to how things work, it's so "light" that we bake it into our products, and increasing the "cost" causes an exponential cost to end users because it's so widely adopted and essential. This industry seems to want to eat itself, taking things that work decently well and noodling on them until something much more costly comes along, why on earth would we take DNS before tackling the much more necessary project of fixing email?
- Daho0n 6y ago
- PurpleFoxy 6y agoThis problem is pretty much fixed in Firefox. The cloudflair doh server updates records very quickly. Also has the side effect of unblocking the pirate bay for me.
- yakubin 6y agoIn my experience, updating DNS is surprisingly fast, even though I typically set my TTLs to 3 hours. Typically I don't have to wait more than 2-5 minutes. Faster than e.g. updating an avatar on GitHub.