5 ms·
Quad9 Files Official Objection Opposing Sony Music’s German Court Ruling
- GekkePrutser 5y agoThis kind of block will stop absolutely no-one. It's just for show. Edit: Source: https://www.pcworld.com/article/2047227/downloading-increases-in-the-netherlands-despite-pirate-bay-block-study-finds.html https://www.pcworld.com/article/2047227/downloading-increase...
- opheliate 5y agoMaybe no-one technical, but here in the UK where DNS-based blocking is very prevalent, I know most of my non-technical friends don’t know how to access a website that’s been blocked in this way, and wouldn’t think to look for mirrors. I’ve tried to explain the process of piracy via torrents to people and it just goes over their heads.
- tialaramex 5y agoYou don't need mirrors, you just need a DNS server that doesn't implement this policy. Historically the government reaction to that was to censor the DNS protocol itself. Trouble is, by the time they got around to legislating for such things, DNS is already optionally encrypted. In Firefox for example General -> Networking Settings -> Enable DNS over HTTPS
- josephcsible 5y agoAnd you don't think Sony Music is going to make them block use-application-dns.net next, for being a circumvention tool or something?
- tialaramex 5y agouse-application-dns.net is a canary for the default behaviour, but the configuration switch I described is a deliberate user choice, so the canary isn't relevant.
- GekkePrutser 5y agoAh but I'm not talking about getting around the actual DNS part (even though that is indeed trivial). I'm talking about obtaining the content. Sooner or later they'll just ask a techie friend where they can still get their sweet torrents and they're back in business. They've blocked the pirate bay in the Netherlands for a long time and it was hardly effective at all. In fact it did the opposite: https://www.pcworld.com/article/2047227/downloading-increases-in-the-netherlands-despite-pirate-bay-block-study-finds.html https://www.pcworld.com/article/2047227/downloading-increase... And finally, don't forget: The people who are using Quad 9 are people who do know what they're doing. Otherwise they'd be simply using their provider DNS.
- Aissen 5y agoSo it begins. Cloudflare, Google DNS and others to follow. IMHO they went after quad9 because they advertise that they already block some domains, based on some lists. They'll probably argue that it's simple to add to their system.
- cedilla 5y agoThat's exactly what they claim. The objection argues that these blocks are not comparable though, mainly since the malware domains are filtered globally, where that's obviously impossible for local filters based on regional court decisions.
- vmoore 5y ago> Google DNS Google's 8.8.8.8 / 8.8.4.4 offering is actually very forgiving. Most pirate sites now have multiple TLDs and advertise the latest TLD in use on social media. New TLDs usually arrive when there is pressure by Google or even LEAs to censor specific domains.
- deleted 5y ago[deleted]
- bwoodcock 5y agoThey went after Quad9 (and not Google, Cisco, and Cloudflare) because Google, Cisco, and Cloudflare are all still hiding behind the Northern California District Court, where there are no consequences for privacy violations. And the US isn't a signatory to the Lugano Convention, whereas Switzerland is. Sony began this attack just a few days after Quad9 re-domiciled to Switzerland. An unexpected and unfortunate cost of having a binding privacy policy. I gave a talk about this at the last DEF CON: https://media.defcon.org/DEF%20CON%2029/DEF%20CON%2029%20video%20and%20slides/DEF%20CON%2029%20-%20Bill%20Woodcock%20-%20Defending%20Against%20Nation-state%20%28legal%29%20Attack%20-%20Live.mp4 https://media.defcon.org/DEF%20CON%2029/DEF%20CON%2029%20vid...
- J-Kuhn 5y agoFrom a technical point: How would DNS blocks even work if DNSSEC is used?
- formerly_proven 5y agoNXDOMAIN can't be signed. DNSSEC only insures that a positive answer is traceable to the trust anchor.
- bawolff 5y agoNSEC can and are signed under dnssec. Its impossible to prevent denial of service generally, but you can use crypto to detect when it might be happening.
- formerly_proven 5y agoThanks for the correction, I wasn't aware of the NSEC/NSEC3 "non-existence" proofs.
- detaro 5y agoWhat difference would it make to you as a user between "this domain doesn't exist" and "this domain doesn't exit, but I refuse to give you valid proof that it doesn't" (or even no answer at all)? (NXDOMAIN is also somewhat special in DNSSEC and not signed by default, and requires special mechanisms to handle (NSEC, NSEC3), but IMHO that's not even very relevant to the block scenario)
- AnthonyMouse 5y ago> What difference would it make to you as a user between "this domain doesn't exist" and "this domain doesn't exit, but I refuse to give you valid proof that it doesn't" (or even no answer at all)? If you're validating then the second answer should cause you to regard the reply as invalid and retry the request, possibly using a different DNS service.
- perch56 5y agoIf you want to support them as an individual, donate through PayPal. https://www.paypal.com/donate/?hosted_button_id=PSNWM3WUSAZU2&source=url https://www.paypal.com/donate/?hosted_button_id=PSNWM3WUSAZU... If you are an individual: Quad9 relies entirely on sponsorship and support from individuals and companies who believe in our mission, and who benefit from our protection of end users. We need resources to fight this ruling, and to continue our mission of providing security and privacy to end users. Your comments on social media to amplify the awareness of this issue and engage in civil discussion on the topic are welcome. Please help by donating via Paypal.
- WarOnPrivacy 5y agoDone.
- bwoodcock 5y agoThank you! Very much appreciated!