16 ms·
Quad9 and Sony Music: German Injunction Status
- apazzolini 5y agoI've been a happily paying customer of Spotify for nearly a decade now. This is the kind of shit that makes me reconsider returning to piracy.
- superkuh 5y agoThis, again, is like the local phone company being forced to block your ability to call people because of an assertion that the person being blocked has infringed on their copyright. It's clear that the phone company has nothing to do with the situation and it's a massive legal overreach to compel them to get involved. But media megacorps have never cared about logic or sanity. They make their own reality with their piles of money and lawyers.
- lugged 5y agoThey don't call them the mafiaa [1] for nothin. [1] http://mafiaa.org/ http://mafiaa.org/
- alerighi 5y agoAnd yet is what they do in my country to “close” piracy sites: ask the national internet providers to block the resolution on that domains. Of course in most situations you can just change the DNS to 1.1.1.1, or if the provider redirects all DNS request to their server just use DNS over HTTPS…
- sethgecko 5y agoUntil Sony sues Cloudflare/Google etc
- Tijdreiziger 5y agoI'd love to see that for the entertainment value alone!
- RamRodification 5y ago> in most situations you can just change the DNS to 1.1.1.1 Or maybe 9.9.9.9 (quad9)! :)
- ThatMedicIsASpy 5y agouse 9.9.9.11 for ECS support
- ajsnigrutin 5y agoI mean.. technically is not "blocking your ability to call", but just unlisting them from their phonebook and phone-number-information-service. But in the end, this means that people will start using the alternatives more.... hopefully.
- bwoodcock 5y agoNo, actually, that was where things stood BEFORE this injunction. The phone company is an intermediary party, with a relationship to at least one of the parties to an alleged infringement. The whole point of this injunction is that it applies to us as a party with NO relationship to the alleged infringing parties. It relies upon a German law that says that uninvolved bystanders are also liable.
- gabereiser 5y agoCaving in to Sony’s lawyers again. DNS resolution is not copyright infringement and someone needs to put Sony/BMG in their place and make them go after those who are actually infringing instead of those who are providing internet backbone services.
- djrogers 5y agoNot sure you read the article? This isn't a case of caving to the lawyers. Those lawyers got a JUDGE to grant an INJUCTION. Once that happens, you're not caving to lawyers - you're going to follow the letter of that injunction while you appeal it, or throw up your hands and follow it forever. Also FTA: "We have retained counsel, and we are in the process of filing an objection to the injunction, though we are required to comply with it." So they're not throwing their hands up... --edited for spacing
- rectang 5y agoIt's more that Sony has effectively bought "justice" (i.e. a court decision) favorable to its interests by bringing overwhelming legal resources to bear.
- airhead969 5y agoThe corporations own all elected officials (executive, legislative, and judicial) and MSM except some ostensible, powerless dreamers who think they can make a difference nibbling on the ephemeral periphery. The most rational and bravest voices in media (Hedges, Chomsky, Nader, Maté, Blumenthal) are currently ostracized as effectively-mute dissidents, conflated with conspiracy theorists and religious zealots for their crimes of factual, professional reporting. "It is difficult to get a man to understand something, when his salary depends on his not understanding it." ― Upton Sinclair The prevailing filter bubble of the bourgeoisie and the rich is intent on remaining secure at all costs, assassinations included. Just look around the world where journalists are murdered most and then where they are deplatformed.
- 5y ago
- irthomasthomas 5y agoThis is the equivalent of mandating that every freight company, shipping agent or port inspect every box for fakes or infringing materials.
- yarcob 5y agoNo, it's more like mandating freight companies do not deliver to certain addresses.
- anderskaseorg 5y agoNo, it's more like mandating map companies do not even list certain addresses in an effort to thwart freight companies from servicing them. A DNS resolver like Quad9 just provides the addresses. There's no allegation here that any infringing content was served by or delivered through Quad9.
- nerdponx 5y agoI could definitely imagine Google being ordered to remove listings for illegal brothels.
- airhead969 5y agoMeh. Some service or another will pop-up to list the fun stuff governments and their corporate crook masters try to squash.
- pyrale 5y ago"Will" ? It's already there. People simply aren't so interested in skirting the bans apparently.
- airhead969 5y agoYep. "Offend our commercial legal monopoly for exploiting creators, and the laws and legal precedents we bought order all cartographers to damnatio memoriae your IP and/or location."
- an_opabinia 5y agoThe irony is, I’ve never experienced DNS problems with invite only piracy sites with quality and quantity 100x the public ones. And doubly so, because I’m sure a lot of Sony employees use them.
- varispeed 5y agoI wonder why companies like Sony only seem to be focusing on attacking small business. I remember if you wanted pirate content, Google itself was the best search engine for that. You could (and likely still can) find almost anything and yet these companies don't seem to be taking Google to court. Wonder why?
- dgb23 5y agoTo add: this is not even a small business, but a non-profit with a security mission.
- nvarsj 5y agoGoogle reportedly receives 2 million DMCA requests a day to take down content including pirate links on search.
- KMag 5y agoIt least at one point in the 2006-2010 range, Google would display a Chilling Effects link to the actual DMCA takedown request when some of your search results were censored by a DMCA takedown. The DMCA takedown request is required to specifically enumerate the censored URLs. The end result was a DMCA takedown often resulted in an indirect "Certified by Sony" link to non-fake infringing copies.
- bwoodcock 5y agoThe other two large recursive resolvers, Google and Cloudflare, are protected by the District Court of Northern California, and more generally, by US law. Although we didn't find out about it until last Friday, the court documents show that Sony got this attack underway just thirty-five days after we moved out from behind the shield of the US courts.
- unethical_ban 5y agoI really, really don't like DNS censorship. I think that if a site is bad enough to warrant being taken down, it should be taken down by the authorities that host it. OR, these governments should have a formal enforcement regime that monitors and sends takedown requests to DNS resolvers. Then, high-tech people will either use .onion, or we will see again the popularity of alt-root DNS services. So will the alt-root DNS website (whose domain is on the "official" root) be taken down, because it is a pointer to a pointer to potentially illegal stuff? Where does it end? Or will the goal be simply to make it hard enough that only 1% of people know how to access it, vs. 20%?
- programmarchy 5y agoCheck out blockchain domains [1] which implement an NFT standard for domain names. So far Opera and Brave have added built-in support for .crypto and there are extensions for other browsers. [1] https://unstoppabledomains.com https://unstoppabledomains.com
- ryan29 5y agoI've looked at blockchain based domains. There's also ENS (.eth) and HNS (namebase.io). The biggest problem with them is they're a huge pain to purchase. You need to buy their vBucks style coins first (ETH or HNS) and many western governments treat those like a security. That makes it tough for someone like me who wants to buy legit, brandable domains in those systems. So the only people left are the ones mining coins and skirting KYC/AML laws and I think that leads to a scenario where they'll gain a reputation of being a "nefarious" technology even though there's _some_ merit in the idea. DNS based censorship by western countries is a risky game IMO. That makes the system vulnerable to a developing country coming in, setting up alternate DNS roots, and refusing to filter / censor for copyright infringement. It won't take much for western users to learn they need to use a foreign search engine to find things the western countries want censored. China's citizens will be using US search engines and US citizens will be using Chinese search engines. Lol.
- Karrot_Kream 5y ago
- kayson 5y agoI wish they hadn't complied. It wouldn't be the first time a tech company stood up to this kind of thing. (Github and youtube-dl, Digg and HDDVD key, etc). Not familiar with German law. What would happen if they simply ignored the injunction?
- mullen 5y agoThe police might come take their DNS servers.
- iratewizard 5y agoThat would have been really nice, but I can't blame them. If I were in their position, I would save my company and employees first. Making noise about it comes after their wellbeing.
- airhead969 5y agoThat's not how activism works. No one will pay attention and writing White House online petitions doesn't do anything either.
- bwoodcock 5y agoWe don't have any staff based in Germany, and none of us are traveling to Germany until this is settled.
- joshuaissac 5y ago
- curiousfab 5y agoFun fact: The same court ruled in 2008 that access providers may not be forced to block DNS: https://www.telemedicus.info/lg-hamburg-bestaetigt-wirkungslosigkeit-von-dns-sperren/ https://www.telemedicus.info/lg-hamburg-bestaetigt-wirkungsl... This Hamburg court in particular has produced hundreds of scandalous injunctions over the years, many of which were overturned later.
- xxpor 5y agoUnfortunately Germany has a Civil Law system, so precedents aren't binding.
- jimbob45 5y agoCan you explain what you mean by that? I know precedent law in the US doesn’t guarantee a verdict but it vastly speeds up the appeals process.
- eindiran 5y agoSee: * https://en.wikipedia.org/wiki/Common_law https://en.wikipedia.org/wiki/Common_law vs * https://en.wikipedia.org/wiki/Civil_law_(legal_system) https://en.wikipedia.org/wiki/Civil_law_(legal_system) "The civil law system is often contrasted with the common law system, which originated in medieval England, whose intellectual framework historically came from uncodified judge-made case law, and gives precedential authority to prior court decisions."
- skywal_l 5y agoThere are precedents in civil law too. It's just that judges have less leeway in "creating" law than in the common law systems and thus precedents are not as binding because the law is supposed to be already laid our precisely. And civil law systems are not all tuned the same way.
- ChuckNorris89 5y ago
- ulnarkressty 5y agoQuite a lot of these lawsuits happening in Germany against local businesses. But can a German court really order a company located in Switzerland to comply? I thought that was the main selling point of Swiss-based companies.
- intellirogue 5y agoThe "almost-EU" countries (Switzerland, Norway and Iceland) have a treaty with the EU covering cross-border civil disputes, called the Lugano Convention. That gives the Hamburg court jurisdiction in this matter.
- bwoodcock 5y agoWithin reason. https://www.reuters.com/article/swisscom-court-idUSFWN20M0KT https://www.reuters.com/article/swisscom-court-idUSFWN20M0KT We'll see what happens.
- jaywalk 5y ago> But can a German court really order a company located in Switzerland to comply? They sure can! It's just one of the many "perks" of the EU.
- intellirogue 5y agoSwitzerland isn't in the EU. In this case it is a separate treaty which allows it.
- the8472 5y agoDNS is distributed, you can always run your own resolver https://openwrt.org/docs/guide-user/services/dns/unbound https://openwrt.org/docs/guide-user/services/dns/unbound
- s800 5y agoHave there been any attempts/successes to issue injunctions against roots?
- nerdbaggy 5y agoI wonder if any legislation can make the root servers block things
- JoshTriplett 5y agoIt could make the root server hosted in one country do so, at which point hopefully the other roots would simply de-list that faulty root server (and start seeking to establish another root server elsewhere).
- giobox 5y agoThe root servers (ICANN) are still under the remit of the US department of commerce, so it’s theoretically possible for US legislation at least.
- 0xcde4c3db 5y agoI might be misunderstanding something since I've never been a DNS expert, but wouldn't root servers only be able to block at the level of entire TLDs? Not to say that governments couldn't be interested in doing that, but the flexibility seems limited (without e.g. requiring the root server to return government-approved servers and implementing the blocking on those servers).
- deleted 5y ago[deleted]
- nybble41 5y ago
- deleted 5y ago[deleted]
- Y_Y 5y ago"The Net interprets censorship as damage and routes around it". - John Gilmore
- mnouquet 5y agoWorked so well for Parler, Damore, or even Trump.
- lscotte 5y agoWe're in a very dark period where people are fine with censoring viewpoints that they don't agree with, especially around political boundaries. It's very unfortunate - censorship is censorship, plain and simple.
- NaturalPhallacy 5y agoYup. I gave up arguing with the posters and even founder of TechDirt about it. They call it 'content moderation' when they agree with it and censorship when they don't, based on whether it's left leaning (Good™) or right leaning (Bad™). It's so bizarre how the left controls the house, the presidency, academia, the mainstream media for the most part, all of the big tech companies, but complain that the Republicans are the fascists. We either have free speech, or we have fascism. And it's not the right trying to censor and cancel people, it's the authoritarian left who feel like they know better than everyone else. Very irritating as a libleft, because they read my disagreement as being right leaning rather than freedom loving.
- emj 5y agoIf you are a freedom lover foremost perhaps you should work more on making the issue seperate from right vs left rhetorics. Always look at why someone wants to censor, rather than just assume it's because of ordinary left vs. right. The scale seems to a lot more binary in the US than I'm used to. It's not a left right issue, we do need to have sex-ed in schools, you need to talk about homosexuality, and the problem with nationalism even the american flavour. I don't even think those are issues that all left leaning people agree on. Dig deeper.
- T3RMINATED 5y agoIf Quad9 complies, I would stay away from Quad9 services as they are not fighting for the right thing.
- varispeed 5y ago> Artists deserve to be compensated, I like this dig at Sony. I don't believe for a second that Sony has any interest of the artists in mind. It's all about their own profits at all cost. They wouldn't care in the slightest if artists died of hunger. But that's just my opinion from dealing with the record labels myself.
- airhead969 5y agoSony BMG can talk a long walk off a short pier. They're blood-sucking, rent-seeking, cannibal vampires. If people would watch it, they would pay homeless people to dance and fight each other in LA's canals during a storm, monetize it, advertise it on all platforms, and they would still sleep OK at night.
- jfengel 5y agoIt's true. Sony doesn't care about artists, any more than your boss or company cares about you. But they are, nonetheless, the ones paying the artists. Not nearly enough, and with plenty of shenanigans, but that doesn't change the fact that every movie ends with a long, long, long list of people who got paid for working on it -- by Sony. It's disingenuous for Sony to pretend they care about anything other than their own profits. It's just tugging at heartstrings. Few of them actually get a share of the profits. They work for a paycheck. But they've nonetheless got a point: they hire artists, lots of 'em. Some of their profits go into making the next movie. Arguably, that's better than caring about them. I don't particularly like facile capitalist arguments, but Adam Smith's quote about the baker really does apply here: the artists don't need Sony to care, they just need Sony to pursue its own self interest because it happens to also profit them. You won't see me crying over Sony's lost profits, and I'd love for more people to see movies other than studio blockbusters. But I know a lot of people who make movies and they do, in fact, get their paychecks and royalty checks from Sony.
- amarshall 5y agoIs the censorship applied globally or just to their resolvers in or near Germany? Unfortunately the domain names are redacted so it’s not straightforward to test this.
- bwoodcock 5y agoThere is no censorship. This is an ongoing dispute between a court in Hamburg and a non-profit in Switzerland. When the dispute is eventually settled, Quad9 either will or will not be providing service in Germany. https://quad9.net/service/privacy https://quad9.net/service/privacy "Quad9 commits to obey the law in any country in which it operates. Therefore, it will only operate in countries with a rule of law compatible with Quad9's ethics and moral duty to protect users. If a government were to use national law to attempt to force Quad9 to act in a way that would harm users (such as collecting information that might de-anonymize an at-risk individual), Quad9 would withdraw from operations in that country. This does not mean users within that country would be prevented from using the Quad9 service (unless the country itself prevented them); the service will operate from locations in nearby countries."
- mijoharas 5y agoGreat stuff. I respect your commitment to your users.
- api 5y agoSo now we know why the push to centralize DNS even more... ?
- djrogers 5y agoI can see why one would be concerned about a heavily centralized DNS, but what I've experienced in the real world is that today's DNS gives me infinitely more options than I had back when I started on the Internet. Back in the day, you were often limited to one or two widely known public servers (MCI's for example) or your ISPs. Today I have tons of providers of public DNS, all with different advantages and tradeoffs, including paid features and support. This alone is radically better than the choices we had ~20 years ago. Add to that the fact that I can run my own caching resolver without reading a 642 page paper bound book (see pihole vs a dog-eared copy of DNS and BIND by Liu and and Albitz), and we're far from the dystopian nightmare you seem to be referring to.
- jsjohnst 5y ago> you were often limited to one or two widely known public servers I have a found memory for the days when you could still use ns.sun.com (192.9.9.3) as a recursive resolver as it was such an easy to remember IP (for those days anyway).
- Dah00n 5y agoUnless he edited his comment it said nothing of the sort. It states there's a push and there is.
- sebyx07 5y ago1.1.1.1 is the solution?
- omoikane 5y agoAlso 8.8.8.8
- airhead969 5y agoCloudflare's public DNS would need to be within this jurisdiction or be hit in a similar way in another jurisdiction. Edit: whoops, I thought Quad9 was an ISP.
- spinax 5y agoWhat makes you think CloudFlare (or Google/8.8) could not be hit with the same legal injunction? This is a court order and Quad9 must comply, as would CloudFlare or Google.
- cmeacham98 5y agoI am not aware of 1.1 or 8.8 ever being forced to block/change DNS. While this does not prove they won't in the future, considering the popularity of the services this suggests US law is on their side. Additionally, Cloudflare has previously shown commitment to deliver DNS exactly as it receives it with no changes (see archive.me debacle).
- markn951 5y agoExcept in the case of deciding to exclude EDNS Client Subnet, which in my experience completely borks CDNs. Which is why I switched to Quad9 in the first place.
- spinax 5y agoI get what you're saying, but we're talking about a very specific action: a court injunction. Whether or not it will be overturned or invalid is a followup - I am not versed at all on German law but I would assume it's a criminal penalty to refuse to comply with a court injunction (for anything, not just this). As stated in the blog, they will comply and fight the injunction's validity.
- intellirogue 5y agoReading the suit, it is interesting that it is very much based around the fact that Quad9 already blocks resolution for "malicious" domains, and therefore already has a censorship process in place. Basically "you're already censoring, one more domain won't hurt."
- felixg3 5y agoI am curious if this also applies to their unfiltered version 9.9.9.10 then.
- adsche 5y agoHm, but they also offer a DNS without the malware filter. Does that imply that they would not have to block "pirate" sites on the unfiltered resolver?
- slim 5y agoWhich makes their argument about "the cost" mostly invalid
- avh02 5y agoyou can also add *.sony.* to that "one more" list. pretty sure there'd be no law against that - wonder if they'd appreciate it though.
- bwoodcock 5y agoThat's the assertion Sony makes, but that doesn't actually make it true. Quad9 doesn't do any blocking, Quad9 relies entirely upon third-party expert malware analysts to define the blocks. Quad9 only decides what _not_ to block. Also, Quad9 blocks the same malware and phishing everywhere, because we don't know who or where users are. So Sony asserts that this is possible, but they certainly don't demonstrate how it could be done, much less who would pay for it.
- airhead969 5y agoSony: the surreptitious installer of rootkits, COPA violator, and payola bribers. Now, with 50% more suck through DNS censorship!
- _trampeltier 5y agoThe sad thing is, i like Sonys desing and the hardware a lot. But I think now is the point, where I just can't support that company anymore. A bit the same like Windows. Even I was early on Linux for most things, I still allways had Windows beside. But with Win10, I just couldn't agree to the EULA, so im Linux only since then.
- roody15 5y agoThe fact that Quad9 so easily complies = will not use quad9
- annoyingnoob 5y agoYour loss.
- bwoodcock 5y agoOr, the fact that you don't seem to be able to use dig, your loss.
- _aleph2c_ 5y agoMaybe in retaliation to this "legal" attack on open infrastructure, DNS providers should de-list Sony domains.
- vorticalbox 5y agoThere is a firefox addon that blocks domains that abuse the dmca system https://addons.mozilla.org/en-US/firefox/addon/barbblock https://addons.mozilla.org/en-US/firefox/addon/barbblock
- getcrunk 5y agoThis would send a very loud message, but is it wise
- seviu 5y agoI was sued in Germany by Axel Springer due to an ad blocker I wrote. The lower court of Hamburg ruled against me. They openly admitted they did not know what they were doing because the case was too technical for them. They were just happy to please the big corporation. Hamburg is a favourite for such cases because they just have no clue about technology. They are just old fashioned. As a small indie developer, I could not afford to keep on fighting. I gave up. I was a psychological wreck. And since it is not binding, big entities can afford to sue you non-stop. Hamburg was the second time I was in a court. I got sued by the same big corporation. I won the first one. Despite not being binding Sony will use this as a precedent and they will start going against the bigger DNS players, till all of them have to comply with their demands.
- ChuckNorris89 5y ago>They were just happy to please the big corporation In Germany?! Never! /s This reminds me how the gyms in Germany were told by the government they were not allowed to collect membership fees during the lockdown but the big chains did it anyway on the basis of "what are you gonna do about it?". So if you wanted gyms to comply, each customer had to take their gym to court on an individual basis but most never bothered. It's crazy, from a foreigner's perspective, with how much shenanigans big business in Germany can get away with legally, considering how strict and bureaucratic Germany is. And don't get me started on customer service.
- TeeMassive 5y agoThus the saying: "More laws, less justice"
- z3ncyberpunk 5y agoget your bank to charge back the card for fraudulent charges to your account
- n_ary 5y agoNope, most banks(specially online-only) will decline your charge back citing some super complex directive that is totally unrelated & you can't appeal. Charge backs will work for no name small merchants mostly.
- kureikain 5y agoIt's amazing Quad9 is run as a non-profit org. I run an email forwarding[0] app and I need to do a lot of DNS query(for spam filtering purpose), I run dnsmasq top load balance between CloudFlare, OpenDNS, GoogleDNS, Quad9 and Hetzner DNS. Quad9 outperform the rest with 2-4x faster and more reliable. In term of reliable I meant they won't rate limit me. If anyone need reliable DNS, Quad9 rocks it. I'll contribute my part on this battle too. Thanks Quad9 --- 0: https://hanami.run https://hanami.run
- Dah00n 5y agoWhile I like Quad9 I get better results (IE. faster, etc.) from Uncensored DNS[1] and unlike most, including Quad9 now, it is, well, uncensored. https://uncensoreddns.org/ https://uncensoreddns.org/
- zinekeller 5y agoI think that you may have just accidentally put them in harm's way (if Sony is reading here), since they're in Denmark (which the Hamburg court could also reach).
- Dah00n 5y agoI doubt they would be successful :)
- deleted 5y ago[deleted]
- bwoodcock 5y agoThank you! We hugely appreciate it! If this were just about us, we could have the Swiss courts throw it out, like US courts would, but that would leave the precedent standing and usable against anyone in the EU. So we need to fight this in Germany, and that's going to be expensive. Eco, the German Internet association, have committed a bit to the legal defense fund, and we're talking with the EFF and Digital Freedom Fund.
- MomoXenosaga 5y agoThis is what the TOR browser is for.
- Dah00n 5y agoNo, this is what DNS sevices like uncensoreddns.org is for.
- rad_gruchalski 5y agoUntil Sony goes after them. Circle of life.
- bwoodcock 5y agoNo, actually, uncensoreddns would have been a much softer target for Sony... They're in the EU, while Quad9 is in Switzerland.
- GekkePrutser 5y agoOh well. I use Quad9. But at least now when a torrent site won't work I'm reminded to turn on the VPN .
- Vaslo 5y agoHow does Quad9 make money? Just through sponsors? Just seems like they don’t have any income with a free service but maybe I don’t understand.
- _ink_ 5y agoI don't get it. Quad9 is Swiss based. How is it relevant what the clowns from the court in Hamburg think?
- _-david-_ 5y agoIf they don't comply they could be blocked in Germany.
- bwoodcock 5y agoYes, both of the above are correct. In addition, I'd have two years of prison if I entered Germany again, which I normally do relatively frequently, to look after our servers in Frankfurt and Munich and Berlin and Düsseldorf and Dortmund and Wuppertal and, ironically, two locations in Hamburg. But more to the point, although the Swiss courts will happily tell Hamburg to get stuffed, that would leave the precedent standing, for application against literally anyone in the EU.
- lehi 5y agoVerizon has also been blackholing routes to ddos-guard for the past few weeks, cutting off access to any sites protected by them: https://torrentfreak.com/why-is-verizon-blocking-pirate-sites-such-as-nyaa-and-mangadex-210608/ https://torrentfreak.com/why-is-verizon-blocking-pirate-site...
- progbits 5y agoI hope this is not frowned upon here but I believe the domain in question is canna[dot]sx. You can confirm this by taking some of the URLs in the report and substituting the blacked out domain with it and it indeed shows the Evanescence album that the document points to. (I got this by doing reverse dns lookups on some of the IPs they list without censoring) Edit: I have tried resolving using 9.9.9.9 and get the same answer as other DNS servers, even running from a VPS in Germany. It appears they have not blocked it yet?
- zinekeller 5y agoHave you tried the .to domain? The .sx domain is recently registered (probably because SME also obtained an injunction against 1&1 and Telekom to block it), and I can confirm that the .to domain is blocked inside Germany.
- progbits 5y agoGood point, it might be a replacement domain that just has the same content so my URL check doesn't mean that is what they requested. As for .to, it does resolve fine for me via 9.9.9.9 from multiple locations including Germany but maybe my VPS IP just doesn't resolve to the right geolocation.
- zinekeller 5y agoEither that Quad9 (unintentionally) haven't included the IP range in the scope or Quad9 is intentionally only applying the filter in residential connections (because business won't engage in piracy, right?) Edit: Resolves in Versatel (which is a business-grade connection). The offending domain is blocked by 1&1's (Versatel's parent) DNS resolvers though.
- ketzu 5y agoIndependent of the current case (and Hamburg rulings in gernal), I haven't made up my mind yet about DNS blocking. The countless analogies don't really help me to find the right approach to handle these kinds of things. First, the "it only increases friction" argument: Basically everything is like that. Barely anything is absolute in the regard. If locked doors are effective at stopping most get-ins, it doesn't matter that they can easily be opened with a bit of skill. Second, should every country have to accept everything that is legal to host in any other country, i.e., should countries be allowed to make and uphold their own laws? I mostly think so, but am not sure how to achieve this. Violations can easily be outside of the reach of the country but there is still a desire to prevent the influence. Is DNS resolution an appropriate point to attack this problem? I am not sure, neither from an effectiveness nor an sensibility point of view, but I find the point of view to pursue everyone in their home jurisdiction (if it can be determined at all) convincing either.
- wolverine876 5y ago> should countries be allowed to make and uphold their own laws? I mostly think so Isn't that backward? The question is, should people be free to make their own choices and live their own lives? I don't care about countries, I care about people.
- ketzu 5y agoI think the answer to that depends heavily of ones own philosophical point of view - we may not even agree on what makes people free. I do care about countries as a governing body for the society that creates it, as I think societies should be allowed to self govern. Further, as I am not an anarchist, I believe that laws and governments are a valid way to do so. It is, however, debatable (even for me) which laws are "okay" for a society to implement on itself. There are laws I would consider fundamentally unacceptable. A mostly uncontroversial example would be slavery.
- wolverine876 5y ago> I think the answer to that depends heavily of ones own philosophical point of view - we may not even agree on what makes people free. I think that's a philosophical debate, but mostly nonsense in practicality. It's not a matter of belief or opinion, for the most part; it's not hard to understand. It's just trendy for authoritarians to attack human rights as some subjective matter of relativistic ideas - that would be convenient for them. > societies should be allowed to self govern People have a right to self-govern, and to protect that right and others, 'governments are instituted among humans'. The word 'society' is often a construct used by the powerful to justify their control of the weak - the powerful are 'society', they assert, kind of like old-fashioned divine appointment.
- hlieberman 5y agoThough they redacted the domain name at issue, they failed to redact the IP address that it resolves to. As a result, I can say that the domain at issue is www.canna.to. Further confirmation of this is that the banner of the forum associated to that page, board.canna.to, has a banner warnings its users that it's moved to board.canna.tf to avoid the DNS block ("Um einer DNS-Sperre auch des Boards vorzubeugen, haben wir es von canna.to abgekoppelt.").
- deleted 5y ago[deleted]
- 1vuio0pswjnm7 5y ago"The assertion of this injunction is, in essence, that if there is any technical possibility of denying access to content by a specific party or mechanism, then it is required by law that blocking take place on demand, regardless of the cost or likelihood of success." Technically, this block does not stop anyone from getting the IP address for a domain. Anyone can resolve a domain name using public information that is disseminated from domain name registries, domain name registrars and other authoritative DNS providers. Quad9 is just a third party DNS provider, not an authoritative source for IP addresses. In theory, third party DNS providers could refuse to provide (resolve) the IP address for any domain name. They could do this on their own accord, to suit their own interests, or at the behest of anyone, e.g., an end user, a financial contributor (donor), an interested corporate partner, or perhaps pursuant to a court-ordered injunction. In fact, this in exactly what Quad9 does: they block domains. They advertise this capability on their website, where even the most non-techical reader could find it. From the "About" page: "Quad9 blocks against known malicious domains, preventing your computers and IoT devices from connecting to malware or phishing sites." Third party DNS has a number of potential problems; filtering is one. Funny how people have literaly turned that problem into a selling point. For example, OpenDNS, now part of Cisco, started a business doing DNS-based filtering. Personally I fail to see why third party DNS (ISP-provided DNS or so-called "open resolvers") remains a preferred method of retrieving IP addresses or other RRs. IMO, there is no technical advantange anymore. Many years ago I wrote a system for resolving domains without using recursion, using only authoritative queries, never setting the RD bit. It was very fast. Faster than a cold cache, IME. It could actually get faster as it acquires more addresses of authoritative servers, because it does not need to look them up again. It "learns". The best aspect though is that there are no unecessary third party middlemen. Third party DNS providers are not authoritative sources for any RR. They are middlemen. They do not operate for free. They are potentially subject to influence from whomever pays the bills. People often discuss "privacy" when they discuss third party DNS service. IMO, using a shared third party DNS cache seems antithetical to "privacy" (not to mention "security"). In any event, it enables filtering by someone who is not an authority for the DNS data they are serving, a middleman. This is the view of an end user, not a corporation nor a developer working for one.
- zinekeller 5y ago
- aorth 5y agoRidiculous! A terrible precedent and failure of logic. I'm struggling to find words to express my frustration. They don't even list the domains that we aren't allowed to resolve! Can we use this precedent to sue the US government in court for using DNS to kill Yemenis (drones run software like libc, libc uses DNS), or perhaps to sue Kellogg's for making breakfast cereal that was eaten by someone on the morning they decided to kill someone?
- dhaavi 5y agoIf anyone from Quad9 is still here, I have an interesting suggestion. While finding a legal solution, the resolvers could mark if a block was done due to a legal reason (ie. censorship), so that clients can react to that and ask another resolver instead. If enough resolvers would adhere to this practice, it would render these censorship attempts useless. Of course, client software would need to support this too. I haven't talked to the team yet here at https://safing.io/ https://safing.io/, but I think we'd be willing to implement that in our DNS client.