4 ms·
I bet it'll still manage to serve ad pages instead of NXDOMAIN, though. Actually that's what will get them to patch up.
by systems_glitch 3y ago
I bet it'll still manage to serve ad pages instead of NXDOMAIN, though. Actually that's what will get them to patch up.
- wtallis 3y agoIsn't the ads-instead-of-NXDOMAIN attack the one thing DNSSEC is actually good at protecting against? So I would expect the guilty ISPs to avoid providing any form of DNSSEC support whatsoever, and thereby avoid consequences of any of DNSSEC's downsides.
- tptacek 3y agoNo, DNSSEC does nothing about ads-instead-of-NXDOMAIN. DNSSEC is server-to-server. If you rely on your ISP's resolver server, they can ignore DNSSEC and feed you whatever they want. If you run your own validating recursing resolver, you don't have the ads-instead-of-NXDOMAIN problem in the first place.
- wtallis 3y agoWho relies directly on their ISP's DNS servers? Isn't the ordinary use (for residential networks, who are the targets of the attacks in question) that your router is running dnsmasq and handing out DHCP leases that instruct hosts to query that dnsmasq instance?
- londons_explore 3y agobut that dnsmasq instance is configured by default to consult the ISP's DNS servers by default as upstream.
- wtallis 3y agoRight, but it has a DNSSEC option that when switched on can protect against this attack (provided the ISP isn't stripping all DNSSEC info from their replies), at the cost of suffering the other consequences of attempting DNSSEC validation. Not a great solution overall, but it does exist.
- tptacek 3y agoLook, you're either recursing or you're not. If you're not recursing, you're not really validating DNSSEC records. If you are, you're not vulnerable to NXDOMAIN ads. The NXDOMAIN thing is in fact not a good use case for DNSSEC. That's all I'm saying here, I'm not making any broader claim than that. Of course you can just install a recursive resolver on your router. But then you don't need DNSSEC!
- xz53 3y ago> If you're not recursing, you're not really validating DNSSEC records. Nope, validating in stubs is a thing. systemd's resolved does it. Apple's high-level network frameworks do it if you ask as of a couple of years ago (they've been back and forth on DNSSEC in their lower level API for longer than that). I'm not sure how well they work but they're there.
- tptacek 3y agoA validating stub resolver is effectively a recursive resolver proxying through another recursor. At the point where you're going to do that, you might as well just run a recursive server. Either way: you don't have the NXDOMAIN problem. I really don't think there's a way to get around this. It's not dispositive of DNSSEC (other things are!), it's just not a real use case?
- xz53 3y ago> A validating stub resolver is effectively a recursive resolver proxying through another recursor. At the point where you're going to do that, you might as well just run a recursive server. Every iPhone on the planet might as well be a recursive resolver? Yeah, nah.
- tptacek 3y agoYeah, yah. Watch the WWDC video on how the validating stub resolver in iOS works. They even call it a recursive resolver.
- emmelaich 3y agoJust about everyone in Australia, at least since our NBN was forcefully introduced. (Nearly) all the wifi/routers supplied with NBN are locked to the ISP's DNS. You can arrange to get your own wifi/router and of course you can set your own individual machine to ignore DHCP settings. But that would be rare.
- harry8 3y agoNever heard of a consumer router you can't switch off as a dhcp server for the local network. Also never seen one where you can't configure the ip of the nameserver being handed out for clients to use. Which ISPs actually do this? That said friends don't let friends do anything else than install pi-hole as the dhcp server using unbound for dns. It's never too late but do it today. I'm 100% sure this is possible in Australia.
- lm411 3y agoNot a consumer router, but the cable modem / gateway provided to me by Shaw Cable (now Rogers) in Canada does not allow me to shut off DHCP or customize the DNS servers it provides DHCP clients. I can and do put it in bridge mode and use my own router, but I was quite surprised and miffed to see this. First time I've ever come across that. The router is a Comcast / Xfinity XB6 and I've been told that this is a "feature" of all of Comcast's routers / gateways.
- harry8 3y agoClarifying: so you connect $something to the cable modem. Make a dhcp request and get back your public ip (and some dns servers). But it isn't doing nat or handing out local addresses to your local network. Right? _Or_ it's a combined modem-and-router-in-one which manages your local subnet for you and you can't configure how it does this at all beyond switching the router part off and using a separate router. That sounds nuts?
- Georgelemental 3y agoI've seen this with ISP routers in France (Orange).
- st3fan 3y agoIt usually forwards to the ISP DNS or just configures the ISP DNS directly via DHCP.
- systems_glitch 3y ago99% of everyone who's just a consumer, I'd guess. Probably the only time people change over is when there's a DNS block on something from their ISP (work, school, commonly do that).