16 ms·
Dear EU: Please Don't Ruin the Root
- ahubert 5y ago(author here - if there are any questions, please let me know!)
- jollybean 5y agoWhy is the EU trying to regulate outside it's jurisdiction? Why doesn't the EU simply provide a 'core' set of servers, which they operate to a high degree of fidelity and robustness so that 'should something go wrong' ... then the EU still has these resilient services to reply upon? I don't see how someone doing a public service should arbitrarily come under such scrutiny.
- guerrilla 5y ago> Why is the EU trying to regulate outside it's jurisdiction? My first question is are they or is this the authors view?
- latk 5y agoIt is primarily the authors view. The proposed regulation – like many EU regulations – can also apply to non-EU entities. In this sense, the EU does try to exert extraterritorial jurisdiction. However, this is constrained to the case where the non-EU entity targets people in the EU, so somehow participates in the EU market. The origins of this “targeting criterion” actually come from consumer protection cases, where it's easy to understand: if you advertise your goods or services to people in a particular country, you'll have to play by that country's rules.
- jollybean 5y agoNone of these systems advertise their goods or services anywhere really. So that's going to be a funny day in the ECJ.
- dncornholio 5y agoI can make the analogy that public transport is a public service, but that doesn't mean people have to drive in old and unsafe busses and trains right?
- BuyMyBitcoins 5y agoIt’s the nature of governments and bureaucracies to try and control as much as they can. The kinds of people who draft these regulations aren’t interested in limited legislation. The United States is particularly guilty of this - we frequently demand that other countries follow our regulatory rules, especially around banking and “anti-terrorism”.
- kazen44 5y ago> It’s the nature of governments and bureaucracies to try and control as much as they can. The kinds of people who draft these regulations aren’t interested in limited legislation there is not really any other way to play the geopolitical game sadly. Every goverment on earth is doing this to keep themselves stable, some are just far more succesfull then others.
- emouryto 5y agoWhy not? Let's see... the past year the was a big scandal because apparently multiple non-profits were selling the .ORG top level domain name for $1B. They got these top level domain for free from the US government (or some institution thereof). I would certainly like the EU to regulate more of the Internet instead of it being an US territory.
- martimarkov 5y agoThis is ICANN’s responsibility and not root DNS servers. They are completely separate entities. If you dislike this go shout at ICANN. It’s was US organisation - now it’s a “private” one[1] [1] https://www.icann.org/en/announcements/details/stewardship-of-iana-functions-transitions-to-global-internet-community-as-contract-with-us-government-ends-1-10-2016-en https://www.icann.org/en/announcements/details/stewardship-o...
- herbst 5y agoIt is still a US company regulated by US laws isnt it?
- krona 5y ago> I don't see how someone doing a public service should arbitrarily come under such scrutiny. It doesn't seem arbitrary to me. The service provided exists in many EU countries, and therefore must eventually be harmonised. This is the prime directive of the project.
- jollybean 5y ago"and therefore must eventually be harmonised. This is the prime directive of the project" That's not a very good prime directive. Don't regulate things that don't need to be regulated, i.e. unless there is a very material benefit from it. If the EU is concerned about WW3 level resiliency for these services, they can accomplish that themselves with a few cord, 'hardened' services that meet their criteria. For 'regular operations' it seems we're going quite well right now. Unless there is a threat posed by these heretofore independent operators ... then I'm don't see any obvious material benefit here. I'm wondering if somehow these entities could be compromised in a way that makes them a problem, more so than just 'going offline', in which case, maybe there are some benefits.
- oaiey 5y agoNot they cannot. A DNS request in China is not targeting a European root but a local one. And that can affect a European citizen.
- martimarkov 5y agoUmm idk if I put 1.1.1.1 as my DNS which root is it targeting? The one in China? Or if I put 0.0.0.0 (IP of EU run DNS server backed by EU run root) then is it still China? There is a simpler solution rather than enforcing EU oversight over root DNSes.
- tick_tock_tick 5y agoCloudflare is one of the private operators of root servers mentioned in the article so you would be using the F root server. https://blog.cloudflare.com/f-root/ https://blog.cloudflare.com/f-root/
- mattashii 5y agoIt doesn't, really; see paragraph (65) in the document [0]. It states something along the lines of "if you're providing services stationed in the EU, or services directed people that live in the EU, then you must comply with these regulations". Basically, an import regulation for operators that do not have a presence in the EU (but do target the EU market), and an operating regulation for those that have a presence in the EU. [0] https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=72172 https://ec.europa.eu/newsroom/dae/document.cfm?doc_id=72172
- jollybean 5y ago'target the EU market' is vague. These are independent operators, NGOs etc, services being 'used by EU citizens' not really 'targeting Europeans'. From a liability perspective, to the author's point these services I suppose would have to just filter out European sources? Why would they publish a regulation so obviously vague, full well knowing the reality on the ground? Why wouldn't they use language that unambiguously places NASA etc. firmly 'in our out' of the regulations or, some criteria which they would be one way or another? Seems odd.
- oaiey 5y agoThat is exactly how gdpr is set up. Which is good. Regards NGOs: just because you do not make money does not make you a saint. Regards vagueness: if you want to survive in an agile environment without rewriting every second day, vagueness is the way to go.
- EricE 5y ago>That is exactly how gdpr is set up. Which is good. So if the US comes out with "GDPR- The Next Generation" with similar mandates towards the EU would that also be "good"? Asking for a friend.
- oaiey 5y agoFISA courts and the law they are based on? The US is explicitly or implicitly doing this all the time. Or the Hague invasion act which is pretty much that case (US soldier are protected abroad against international treaties).
- oneplane 5y agoIf you want to look at it from that perspective: the same reason the US does it. People also tend to forget that providing a service (in whatever fashion) doesn't exist in a vacuum, there are the services and then there are the consumers of those services and they might have certain freedoms and rights that the locality of the service in question might not honour. Take the right to control your data for example, the US isn't very good at providing that with the services they offer, and they'd rather not have that freedom and rather make those few percent more money.
- kazen44 5y agoAlso, it makes sense in the broader EU strategy of becoming less reliant on the US. The EU has a good amount of soft power, this is just testing testing it's waters in directing policy more directly. (other examples are the Iran deal after the US left, and Intervention in Africa) Geopolitically, this makes a lot of sense, and i think the idea has good intentions, but the implementation of the law is where it falls short.
- guerrilla 5y ago> The current version of the NIS 2 directive explicitly says the EU will regulate the root servers, and therefore NASA and the US Department of Defense in this way Is the latter part of this your conclusion and interpretation? I haven't looked at the source material but are you sure they aren't just referring to root servers operating in the EU or by EU companies. I find it hard to believe they would consider DoD servers within their jusrisdiction.
- tester756 5y agoI have question about your other post which I found interesting >https://berthub.eu/articles/posts/how-tech-loses-out/ https://berthub.eu/articles/posts/how-tech-loses-out/ You wrote >We barely develop any software here anymore. So even very European companies like like Nokia and Ericsson, that are now trying to tell us that they are building our European telecommunication infrastructure. They’re actually not, they’re getting that built by other people in other countries far away. Anything having to do with server and PC development and manufacturing, there’s nothing left of that in Europe anymore. As far as I've been told, then there are R&Ds in e.g Cracow, Poland or Wroclaw (probably nor R&D) that actively recruit or even train people What are they doing then?
- guerrilla 5y agoYeah, Ericsson employs about 13,000 people in Sweden and I personally know they develop a lot of telco software.
- squarefoot 5y agoMy latest news (~2 yrs ago though) from friends working at Ericsson is that beside hardware they also started outsourcing software to far east entities. I don't have details, but over here they sack about 300 people every year, mostly developers. It might be different in Sweden though.
- BenjiWiebe 5y agoHow many do they hire per year? 400?
- Jolter 5y agoEricsson has hired several thousand engineers per year in the past couple of years, globally. You can see the history of their Wikipedia page for the nitty-gritty...
- squarefoot 5y ago
- oaiey 5y agoWhat is your expectation what a state actor like the EU should do to protect it's citizens infrastructure? Rely on a third party like the US which has secret courts and gives a shit about EU citizen privacy, their property or their lifes? Or give it in the hands of the industry? Which only has one motive: making money. Or leave it unregulated with no safety for no one? DNS is about trust. We need trust into this thing. And honestly: i would not trust DNS offered in China and most likely also not the US, or 99% of the carriers
- sam_lowry_ 5y agoSecond that. The article lacks the good parts. It's clear that the rapporteur has not figured it out yet how to deal with the root DNS servers, but there is a broad consensus over the strategic autonomy goal [1]. One way or another, EU will force its way. Should it do it by e.g. empowering DIGIT to run root DNS servers? They will for sure tender it off to a murky consortium, but at least there will be a positive political move. [1] https://en.wikipedia.org/wiki/Strategic_autonomy https://en.wikipedia.org/wiki/Strategic_autonomy
- oaiey 5y agoI also think that the article is focused too much about the auditing and regulations instead of suggesting a better model.
- EricE 5y agoI love the assumption that there is "a better model." This reeks of the quintessential "let's solve a problem that doesn't exist." Here's an even better and more logical idea - for those who have concerns about the current DNS root server arrangements, what specifically are they? And what would you propose as solutions to their perceived deficiencies? Bonus points if you can raise actual technical arguments and not just feelings.
- oaiey 5y agoFair point. I don't have a different idea in the current geopolitical situation.
- pmontra 5y agoFirst of all, I praise the initiative and the explanation. But not everybody tweets. Is there an email address to send that message to?
- blibble 5y agoif this is true the root servers will simply move out of the EU it's a lot easier to move than say, banking customers
- toast0 5y agoReally, recursive servers should be AXFRing the root zone on a regular basis and not making live queries unless the AXFRd data is sufficiently stale (or on cold start). Icann has some axfr servers setup for this [1]. Some other transfer mechanism for the zone could be used, and almost anything would do as the rate of change is slow and the overall size relatively small. If it's a regular transfer, there's less need to have servers as everywhere as possible as is current policy. Popular TLD servers will likely continue to try in as many places at once as they can be though. [1] https://www.dns.icann.org/services/axfr/ https://www.dns.icann.org/services/axfr/
- swiley 5y agoThe solution here seems simple: their buisness continuity plan is for traffic to fail over to other functioning servers. As long as actually filing the paperwork is easy and the EU accepts the idea that the system is already designed to handle outages this sounds to me like a non-event.
- dncornholio 5y agoAlso I think if you can't handle a bit of paperwork, maybe you should not handle a root server?
- jaywalk 5y agoThis is a whole lot more than "a bit of paperwork" including granting EU representatives the ability to do on-site audits.
- nemothekid 5y agoAs I understand it, the services are run by non-profits. A "bit of paperwork" (and truthfully, it's laughable to call any government mandate a "bit" of paperwork) can quickly turn into something that require legal hours which isn't free.
- zepearl 5y agoI agree about not underestimating the needed effort, but to be fair that service nowadays is absolutely crucial/important for a lot of stuff, private & commercial, involving $$$/lifes (maybe e.g. police etc... run some services over it)/whatever. Probably the criticality/importance of the service must be balanced by appropriate controls/checks/procedures/etc... .
- EricE 5y agoMaybe people's time could be spent better administering servers - i.e. doing useful work - than complying with busywork from bureaucrats intent on solving problems that don't exist. Or even worse, bureaucrats making shit up to not only justify their existence but justify the expansion of their empires - which is exactly what this smells like. There is nothing broken or in need of fixing with how the root servers have worked and work today.
- zokier 5y agoThe concern would be more credible if it came from actual root server operator(s)
- tptacek 5y agoBert Hubert has quite a bit of DNS credibility.
- ahubert 5y agoShrinking at a rapid clip though :-) But thanks! It may also be good to know several root operators provided a ton of feedback on this post.
- EricE 5y ago>Shrinking at a rapid clip though Shrinking by whom? EU partisans or the technical world at large? Quite a difference about who's "shrinking" I couldn't care less about.
- wccrawford 5y agoBert Hubert, apparently. The person you replied seems to be Bert Hubert.
- brendyn 5y agoWith 666 karma. Beware Evil doppelgänger Bert.
- wglb 5y agoWhoosh
- ezoe 5y agoSince EU doesn't have an authority over non-EU countries, they just pond a sand or cut themselves off from the internet like North Korea.
- the_duke 5y agoThe EU is an important enough market that most companies will want to serve EU customers, which means they have to abide. GDPR has forced all companies to at least think about data security and personal data, and given rights to know what data is stored and to demand deletion. Sure, there are annoying consent modals, enforcement is lacking, many companies don't actually follow the law properly, and I've lost access to some websites/apps that don't want to deal with it. But this is a domain where standards are severely lacking, but necessary. No one will do it without being forced to. The biggest downside (for me) is the extra regulatory burden for small companies, but this particular legislation won't affect small companies much anyway.
- nonameiguess 5y agoIt's not totally clear they would really try to do this, but there is no world in which US military DNS servers submit to inspection, auditing, and regulation by the EU. This is nothing like regulating commercial service providers. Even where FVEY reciprocity agreements exist, it's only for products, not for equipment and processes. Even where the US government operates facilities in the UK, there are parts of those facilities non-US persons aren't allowed into. Since the UK left, no EU member state is even a part of FVEY. Granted, DNS is not classified, so those specific restrictions do not apply, but you still can't just go up to the Pentagon unannounced with an EU regulator badge and expect to be let into the building.
- oneplane 5y agoYet the US military wants to inspect the EU's stuff so it seems to be a bit of a one-way thing right now. The US wants to do all sorts of shady stuff to the rest of the world, but as soon as someone wants to do some of that the other way around it suddenly is all sorts of bad.
- Deukhoofd 5y agoFrom what I read in the proposal the core idea of it is solid. DNS is a vital piece of infrastructure, and we should take steps to ensure it keeps working. Putting together task forces to make sure it is secure therefore sounds like a very good idea. Root servers might be out of scope to some degree for this however. Interestingly enough the root servers also aren't mentioned in the proposal itself, nor in the annex listing essential services. They're only mentioned in the lead up, which is the argument for why it's needed. It somewhat feels like they left it in accidentally, especially with the parliament immediately amending to scrap it from the lead up as well.
- ur-whale 5y ago> DNS is a vital piece of infrastructure It is, and therefore it should be 100% decentralized, if only to keep it out of the grabby hands of governments, EU or otherwise.
- madeofpalk 5y agoIs the 12 root server organisations an example of decentralisation?
- EricE 5y agoYup. As well as the decentralization and diversity of the technical operations of each pool. Operational diversity can be as important or even more important than technical diversity since humans tend to be the weakest links in technical chains :p
- deleted 5y ago[deleted]
- ur-whale 5y ago> Is the 12 root server organisations an example of decentralisation? It isn't. Proof: the fact that US random three letter agencies can take down websites.
- madeofpalk 5y agoThe majority of the (long) tl;dr focuses on, and is under the assumption that non-EU RSOs will object and not comply with the NIS 2 directive and... have to shut down or block access to EU? Is there any substance to this actually happening? Is the NIS 2 directive an unreasonable burden on critical infrastructure such as those who run the root DNS? I've never really heard of this "NIS 2 directive" but it seems completely reasonable, and it's even unclear whether non-EU folk like NASA would even be under scope. The only way I can see that being tested is if NASA (or whoever) seriously screw up and have a breach, and get attention on them. If that happens, then good! They deserve the scrutiny! This reminds me a lot of the FUD (primarily) American's were spreading about GDPR which ended up being mostly empty.
- xbar 5y agoWhat FUD about GDPR has been empty? Do you manage much GDPR data?
- madeofpalk 5y agoAll the rubbish claims about the EU bankrupting US mum and pa websites.
- xalava 5y agoInteresting debate. However: - I doubt that the EU meant to directly investigate the pentagon, the opposite might have some history. - The argument that there is redundancy and therefore it is safe is incomplete to say the least. For instance, how heterogeneous are operations, software, potential failures...?
- mordae 5y agoI dunno. I am pretty sure CZ.NIC is going to be OK with this legislation, given they already comply with pretty stringent rules we have now and they even run the actual CERT from the NIS 1.
- deleted 5y ago[deleted]
- nickpp 5y agoWhy not? They already ruined the web browsing experience of hundreds of millions of europeans with their brain dead GDPR/cookie law/privacy note crapola. And they are also busy ruining chat encryption in the name of our own safety, app stores in the name of anti-trust and online ad business in the name of… whatever. The European Union - those who can’t innovate, regulate.
- Bayart 5y ago>The European Union - those who can’t innovate, regulate. What a putrid aphorism. Law is a field of innovation itself.
- xbar 5y ago1. Yes. It is both putrid and inaccurate. 2. Is this law actually innovative? Yes. It is an example of novel EU overreach. If I am Japanese citizen operating a root DNS server in Kyoto, why am I suddenly subject to EU regulation and scrutiny? This is new. EU regulators are innovative. I can think of a lot of other innovators like them. I haven't recalled any that I like. Can you?
- kazen44 5y agolets see: - intra eu Banking which is decades ahead of the US[1] - having universal driving licenses and ID cards valid throughout a continent and beyond[2] 3: High standards of food safety [3] i could name a couple more, but i get you get the point. 1: https://en.wikipedia.org/wiki/Single_Euro_Payments_Area https://en.wikipedia.org/wiki/Single_Euro_Payments_Area 2: https://en.wikipedia.org/wiki/European_driving_licence https://en.wikipedia.org/wiki/European_driving_licence 3: https://eur-lex.europa.eu/summary/chapter/30.html https://eur-lex.europa.eu/summary/chapter/30.html
- Dah00n 5y ago>If I am Japanese citizen operating a root DNS server in Kyoto, why am I suddenly subject to EU regulation and scrutiny? This is new. No it isn't. If Facebook targets EU citizens it's under EU law no matter where it is located. It's the same the other way around. The only difference is that US companies are used to do what ever they want.
- jazu 5y agoI don’t trust the EU. They want to do this so they can censor domain names more effectively (copyright, “terrorism”…)
- ancarda 5y agoHow would this even work? Don't the root servers just help you find TLDs? To take down example.com, they'd have to take down .com, right?
- Denvercoder9 5y agoIf that's their goal (I don't think it is), they are hilariously incompetent at it, as the root servers do not have anything to do with invidiual domain names at all. They only map TLDs to nameservers.
- tyingq 5y agoThe peer comments here aren't quite right. The query that goes to the root server, isn't "what's the name server for .com?". It's "what's the IP for abc.example.com?" The root servers choose to send referrals back for the TLD. They don't have to. They could answer the query directly, or send a bogus authority record for "example.com", etc. So, technically, you could create some chaos in the way you're describing if you ran a root server. (Plus the wrinkle of DNSSEC).
- Quanttek 5y ago> "The non-profit root server operators might have to leave the EU and put up active measures so that no Europeans can use their root servers. They can’t afford to do all the paperwork for NIS 2." I think this is the point where the argument falters. The author is overstating the cost impact regulatory compliance has and understates the non-profit resources. Also, the idea that commercial providers will take over with their competitive edge in regulatory compliance doesn't work, since there is really no impact of such compliance skills on service quality. Everybody provides the same service, so if the operators can comply somehow (even if slow and badly), they are good
- PoignardAzur 5y agoWhile I don't want to dismiss OP's concerns, I vicariously enjoy the turnaround of the US having to worry about someone else's extraterritorial decisions. In practice, though, I don't think it would matter. It's not like (1) the EU is asking to be allowed to install arbitrary programs on root servers or (2) it will start bombing non-compliant servers. Worst case, EU residents (or at least residents using PCs sold in the EU) will only be able to access EU root servers, which will still index 100% of the internet. I'm not super worried.
- coward76 5y agoThe US wouldn't worry, and would make their own internet with hookers, blackjack, zero privacy, taxes, inane regulations and pork, but it would be US controlled. This is how Americans work. Edit: Downvote if you must but it is the mindset of many: https://www.bbc.com/news/technology-53686390 https://www.bbc.com/news/technology-53686390
- will4274 5y agoAlan Woodward seems to be the BBC's go-to person for scare quotes about the internet. In your article: > "It's shocking," says Alan Woodward, a security expert based at the University of Surrey. "This is the Balkanisation of the internet happening in front of our eyes. > "The US government has for a long time criticised other countries for controlling access to the internet… and now we see the Americans doing the same thing." Previously, I saw Woodward giving bad information and engaging in unfounded speculation in an article about Signal - https://www.bbc.com/news/amp/technology-55412230 https://www.bbc.com/news/amp/technology-55412230. > Alan Woodward, a professor of computer science at Surrey University, said Signal was "one of the most secure, if not the most secure, messenger service publicly available". > "Signal employs end-to-end encryption, but goes further than apps like WhatsApp by obscuring metadata - who talked to who when and for how long," he explained. > "Cellebrite seem to have been able to recover the decryption key, which seems extraordinary as they are usually very well protected on modern mobile devices." > He added that if this was indeed true, it was no surprise Cellebrite would have altered its blog. > "I suspect someone in authority told them to, or they realised they may have provided enough detail to allow others - who don't just supply to law-enforcement agencies - to achieve the same result." A good rule of thumb might be, if you see Alan Woodward quoted in support of the article, assume the author doesn't know any genuine experts.
- politician 5y agoBrowsers could alternatively ship with support for Namecoin [1] or Unstoppable Domains [2]. Though, realistically, I'm suggesting Opera or Brave. Mozilla isn't functionally capable of thinking about doing something like that, and I don't think I have to suggest a reason why the other browser vendor wouldn't entertain the idea. [1] https://www.namecoin.org/ https://www.namecoin.org/ [2] https://unstoppabledomains.com/ https://unstoppabledomains.com/
- 542458 5y agoTwo things about these: 1- Having domain names be impossible to seize sounds like an anti-feature for most businesses. If somebody pwns my company or I have a disgruntled sysadmin I don’t want them to be able to indelibly transfer my domain name to themselves with no recourse. Alternatively, if I lose the cryptographic keys to my domain name, am I just completely hosed? 2- No renewal fees ever sounds like an anti-feature to everybody who isn’t a squatter.
- ByteJockey 5y agoThose seem like reasonable objections, but at the same time, the companies implementing these are probably the least susceptible to those problems.
- einpoklum 5y ago> I love Europe, and I want to see the European Union succeed. As a socialist (regardless of my more specific views), I really cannot understand how these two views can be held at once. The EU is an anti-democratic mechanism for concentrating economic and political power in few hands within Europe. Many member states basically forced it onto their citizens despite mass objections and even votes against entrance (or rather, adoption of the Maastricht treaty). And the EU has brought mostly negative effects for most Europeans IMHO. It would have been much better for residents of the continent to bring countries, societies and economies closer without this kind of central control. The proposed measure, of forcing good-will providers of root servers, to have to submit to EU inspections of premises, is a (admittedly rather minor) example of this aspect of the "spirit" of the EU.
- IAmEveryone 5y agoWhat a load of tired cliches... As but one point: only one referendum rejected the Treaty of Maastricht, the Danish one, with a margin of 49:51. In response, some changes were adopted an the Danish people overwhelmingly voted for it in a second referendum, 68:42.
- worik 5y ago"The Internet functions because over 1300 servers provide a starting point for every (website) name used online. These are the root servers." That would be the Web. It is hard to take anything this person says seriously when right at the start they confuse the Internet and the Web.
- yholio 5y agoHe says "name", then ads "website" in parenthesis so non-technical people can understand. Without name resolution, most internet services will indeed fail.
- Jolter 5y agoNo, they are writing about DNS, which is in the core of how the Internet works. Including the Web, yes, but virtually nothing on the Internet would work without DNS.
- stunt 5y agoA lot of things wont work, but you still can't say Web and Internet are the same thing. I also think it isn't fair to nitpick the article for it.
- Jolter 5y agoBut the article doesn’t conflate the web and the Internet. The DNS root servers are necessary for the operation of all the Internet, just like the article says. Not just for the Web.
- akoncius 5y agowhat do you mean? DNS works not only for web. all internet-related things rely on DNS in one way or another. email, chats, FTP etc.
- worik 5y agoSome Internet related things use DNS. A lot do not.
- stunt 5y agoAnyone knows if EU supports these operators or not? Financially or different ways? The EU does support some vital infrastructure projects as far as I remember. I wouldn't be worried about fines. I think the EU is very reasonable and flexible when it comes to enforcing these type of legislations.
- 1vuio0pswjnm7 5y ago"In addition, by downloading this file, every Internet service provider can run their own root server." Any end user can do that as well. The truth is, root servers are not nearly as "essential" as the major TLD servers, like .com, .net and .org What is essential is the ability to download the root.zone file. At least if one wants to track any changes (seldom seen). I always have a copy of the current root.zone file. If the public root servers all ceased operation I would not see any noticeable effects. However if the .com servers went down, I would have to use a local copy of the com.zone which is a much larger file to download (via FTP, HN's favourite protocol to make fun of). An easier alternative is to keep a custom zone file with all the domains that I use regularly. Does any single end user really need access to the entire www. How much of the www does anyone think they have really seen. For example, I have zone files with every domain that is posted to HN, so I never have to worry about being able to read what gets posted here. I can read fast without making any remote DNS lookups.
- gumby 5y agoIf they are worried, they should worry about BGP. The DNS roots are probably not the biggest risk due to their nature (discussed in the post).
- yamellasmallela 5y agoBGP needs a complete overhaul. Every once and a while all the internet traffic "accidentally" gets routed to china due to a "technical mistake" mhmm. Blacklist them.
- rcxdude 5y agoYou'd need to blacklist a lot of the internet. BGP hijackings, accidental and probably not-so-accidental, have happened all over the place.
- krick 5y agoI feel like this manifest seriously lacks the part where it should be playing devil's advocate. I don't have a say in this matter, and I don't know if the author is right anyway. But let's suppose that whoever pushes this agenda indeed is mistaken, and that he's not acting malevolently, and just doesn't see something that the author sees: I'm pretty sure he has some ideas why NIS 2 is necessary. If so, listing (quite speculative) counter-arguments without addressing why "pro-"arguments aren't necessarily correct isn't very convincing. So: why the proponents of this proposal (supposedly) think it's necessary, and why they are mistaken and it actually isn't?
- IAmEveryone 5y agoWhat a non-issue. The linked amendments that thoroughly resolve this complaint have already been adopted by parliament. This article is therefore picking a fight with an old version of a working document.
- dmix 5y ago-indirectly off topic- One of their root servers PDFs said "Due to the critical role that root name servers play, combined with the fact that they are themselves often targets of DDoS attacks" [1] That made me sad. Why mess with the internet which gives us such joy. [1] https://root-servers.org/media/news/Statement_on_DNS_Encryption.pdf https://root-servers.org/media/news/Statement_on_DNS_Encrypt...
- Proven 5y ago> I love Europe, and I want to see the European Union succeed. You have conflict of interest, then, and cannot be trusted. This idiotic idea is leaving the end user just as exposed - if not more - than they are now. Today you are just as unlikely to be cut off as you have always been. But if you're Italy and want to leave the EU without paying back the 400-500 billion euros you owe and they decide to hang onto your DNS servers, you'd probably wish Cloudflare was in charge of DNS.
- Dah00n 5y agoVery little worthwhile reading in this thread. It's mostly people complaining about something they don't understand. Read that article and move on is my advice.