10 ms·
Alternative DNS Roots
- CaliforniaKarl 5y agoI never knew about CHAOS records. I'll have to look more into them. Thanks for the info!
- jamespwilliams 5y agoThere’s also Hesiod (HS) records: https://jpmens.net/2012/06/28/hesiod-a-lightweight-directory-service-on-dns/ https://jpmens.net/2012/06/28/hesiod-a-lightweight-directory...
- ate53 5y agoA possibly needless clarification: The DNS is organised by class, name, and then type. Each class is a seperate space, so ycombinator.com in the IN (Internet) class and ycombinator.com in any other class aren't necessarily the same entities. Types can also be class specific, for example A in the IN class is different to A in the CHAOS class. Types may also only be defined in specific classes like SRV (amongst others) in IN. (Aside: this model is why CNAMEs can't coexist with other records.)
- tptacek 5y agoI'm pretty sure CHAOS just gets used because all the names in class IN have potential meaning to other systems --- you can't just make up random IN names, because you could be screwing up someone else's domain (unless you tediously nest your made-up names under your own domain). But there's no risk of that with CHAOS, so it's a free-for-all for random DNS features. You'd use a new class, like "RANDOM" or something, except that no deployed DNS software knows about that class.
- ate53 5y agoThere's private use ranges for classes and types. They don't have specific mnemonics but you can use the generic ones (eg: CLASS65280 and TYPE65280). CHAOS probably gets used most because that's what BIND happened to do.
- tptacek 5y agoI just sort of assume it's because `dig` already has the string mapped. But maybe people just like typing "chaos".
- walrus01 5y agopeople have been trying to make various competing alternate DNS roots a "thing" for about 22 years now, and I would wager good money that less than 0.01% of the worldwide installed operating system base for client devices are configured to use them.
- tialaramex 5y agoI'd guess maybe 25 years. Pretty sure "alternative" DNS roots were already a thing I had scoffed at by the time I moved out of my first student house in 1998. That's the first place I lived which had Always On Internet Access, 56kbps 24/7 shared between six people over 10base2 Ethernet.
- ryandvm 5y agoDNS is the literally the only compelling use case for blockchain that I have ever been able to come up with (besides paying for contraband). A distributed database that no single entity owns is a perfect match for name resolution. Kind of amusing to me that blockchain DNS hasn't gotten off the ground. What hope do the less compelling blockchains have?
- rasengan 5y agoThere is Handshake [1] which is getting significant [2] adoption [3]. [1] https://handshake.org/ https://handshake.org/ [2] https://twitter.com/opera/status/1476841607005622273?s=20 https://twitter.com/opera/status/1476841607005622273?s=20 [3] https://www.namecheap.com/about/press-releases/21-09-22/namecheap-now-offers-handshake-domain-names https://www.namecheap.com/about/press-releases/21-09-22/name...
- tptacek 5y agoHandshake has no meaningful adoption. It's a pre-mined cryptotoken, traded on exchanges; essentially, the Handshake founders decided to sell the Brooklyn Bridge, which is something that blockchains make feasible. No mainstream browser will ever support Handshake. More's the pity! If the Handshake DNS root heist works, it'd open up new business models for all of us. I had been looking forward to minting ARPCoin and charging everyone to join their WiFi networks.
- rasengan 5y ago
- tptacek 5y agoI work every day on DNS stuff (I own our firm's DNS server, and we're in an environment where it's truly "always DNS") and land naturally on any thread about DNS here. This particular thread isn't about Handshake; it's about setting up an alternate root hierarchy with standard DNS. Regardless of that fact: the guidelines demand that we not make insinuations about other commenters here, and this is the second weird interaction we've had in a row where you've done that. Please stop. My understanding is that you're a strong supporter of Handshake. I think Handshake is a crock. It is fine for us to disagree. But you will disagree with me civilly.
- gerdesj 5y agoDNS over http will eventually destroy DNS as we know it. Thanks Goog n co! DNS at the moment over 53/UDP is manageable and malleable. DNS over http is not and is up to your browser and hence a vendor. Life on the helpdesk will become rather more nasty and worse than it is now and we probably won't get tools to diagnose what is going on inside the browser, and so life for IT will be increasingly crap. I suggest we don't let the FAANGS run the world or the browser.
- smbv 5y agoDoH does not depend on a browser! Try this out with cURL curl --http2 -H 'accept: application/dns-json' "https://1.1.1.1/dns-query?name=cloudflare.com" --next --http2 -H 'accept: application/dns-json' "https://1.1.1.1/dns-query?name=example.com" There are DoH resolvers[0] that you can use that act as a "middleman" between your browser (configured to use a standard DNS server) and DoH (which is more secure and private) [0] https://github.com/DNSCrypt/dnscrypt-proxy https://github.com/DNSCrypt/dnscrypt-proxy
- southerntofu 5y agoI personally consider curl to be a CLI web browser.
- tptacek 5y agoThis makes no sense at all. No part of DoH service involves a browser.
- egberts1 5y agoCorrect, but on the other note, browsers do do involve the DoH.
- windexh8er 5y ago> DNS at the moment over 53/UDP is manageable and malleable. As for that malleable part... You always trust the networks you're on? Because my ISP, in the US, will inject JS into an insecure page load when I'm at 80% of my monthly data cap - I can only assume they're sniffing anything and everything in the clear. It's 2022, we shouldn't consider insecure transports viable. Zero trust, cliche or otherwise.
- 0x073 5y agoNext blogpost: Alternative certificate authority
- merlinscholz 5y agoThat post is in the works for months now, I have a huge list of dumb ideas to go through
- southerntofu 5y agoI'd be very interested if your post contains an OpenPGP-CA review. I'm more familiar with "traditional" ways and that project looked very interesting to me.
- tptacek 5y agoWhat do you want to know? It's quite easy to set up a new CA, and all mainstream browsers have (albeit crappy) user interface for adding them.
- merlinscholz 5y agoThe root ca installation is the boring part, installing a local Let’s Encrypt instance is much more fun
- st_goliath 5y agoFYI: There is CAcert.org[1][2], which attempted to establish a community run authority (long before let's encrypt was a thing) and IIRC Mozilla was at least discussing including their root cert. I remember some years back at Chaos Congress in Hamburg, a friend of mine who was very enthusiastic about CAcert physically met with a few CAcert people to show them his passport and get his certificate signed. [1] http://www.cacert.org/ http://www.cacert.org/ [2] https://en.wikipedia.org/wiki/CAcert.org https://en.wikipedia.org/wiki/CAcert.org
- hansel_der 5y agoimo if cacert had bee included in any major browser, it would have dumpstered the ca-industry in a week. the verification process with passports and physical meetings meant it had better security and crowdsourcing made it effectively free of charge; billions of revenue just gone.
- knowaveragejoe 5y agoIt's crazy how HN, within the space of a decade, went from clamoring for this kind of thing to shitting on it at every turn.