4 ms·
I don't doubt that, it's also trivial for anyone to spin up their own local root mirror to resolve against, I'm just pointing out that maybe Verisign shouldn't
by therealEleix 5y ago
I don't doubt that, it's also trivial for anyone to spin up their own local root mirror to resolve against, I'm just pointing out that maybe Verisign shouldn't be holding onto two. It's even pointed out on their Wikipedia page like some kind of trophy like "Oh hey look, we don't just run 1 we run *2*, that makes us a big deal". :eyeroll:
- profmonocle 5y ago> it's also trivial for anyone to spin up their own local root mirror to resolve against This is a bit of a tangent, but the idea of doing this has always made me nervous. Sure, the root zone is only a couple MB and you can easily set up a cron job to sync it regularly. But if that cron job breaks, it would be very easy not to notice, since it's not like the authoritative servers + glue records for the major TLDs change every day. (Or every decade.) Imagine if that cron job has been broken for 9 months, the IT guy who set it up left 4 months ago, and suddenly a tiny TLD like ".tech" switches to a different authoritative DNS provider. Since it's not a very common TLD you'll never notice... unless some app uses "companyname.tech" for its mobile API - or one of a million other scenarios. It's probably fine if big DNS server operators like Google/Cloudflare or major ISPs mirror the root zone, since they have the resources to make it robust. But small(-ish) IT operations running their own DNS - just use the root servers.