3 ms·
> it's also trivial for anyone to spin up their own local root mirror to resolve against This is a bit of a tangent, but the idea of doing this has always made
by profmonocle 5y ago
> it's also trivial for anyone to spin up their own local root mirror to resolve against
This is a bit of a tangent, but the idea of doing this has always made me nervous. Sure, the root zone is only a couple MB and you can easily set up a cron job to sync it regularly. But if that cron job breaks, it would be very easy not to notice, since it's not like the authoritative servers + glue records for the major TLDs change every day. (Or every decade.)
Imagine if that cron job has been broken for 9 months, the IT guy who set it up left 4 months ago, and suddenly a tiny TLD like ".tech" switches to a different authoritative DNS provider. Since it's not a very common TLD you'll never notice... unless some app uses "companyname.tech" for its mobile API - or one of a million other scenarios.
It's probably fine if big DNS server operators like Google/Cloudflare or major ISPs mirror the root zone, since they have the resources to make it robust. But small(-ish) IT operations running their own DNS - just use the root servers.