3 ms·
Wait a second. Does that mean every DNS request on a Fritz Box network is send to fritz.box first? I query google.com and get google.com.fritz.box every fuckin
by choeger 2y ago
Wait a second. Does that mean every DNS request on a Fritz Box network is send to fritz.box first?
I query google.com and get google.com.fritz.box every fucking time? Shit.
- greyface- 2y agoIf your upstream recursive resolver does QNAME minimization, then the only query that will leak beyond them is for "com.fritz.box", and because that's a NXDOMAIN, no further query for "google.com.fritz.box" is made. If your upstream recursive resolver doesn't do QNAME minimization, then yes. Edit: I stand corrected, see downthread
- jiveturkey 2y agothat’s no saving grace. the fritz resolver would return a result for com.fritz.box so that it can see the full (or next successive) part of the query. qname minimization is useful to defend against on path interception, or data collecting resolvers, not against actively hostile resolvers
- greyface- 2y agoCompletely agree that it creates an unacceptable risk if the fritz.box owner is malicious. I'm just pointing out that currently, com.fritz.box doesn't appear to resolve. Edit: actually, I'm wrong, "NS? com.fritz.box" returns a NOERROR + fritz.box SOA instead of a NXDOMAIN, which causes QNAME minimization to make the full query, which returns an A. QNAME minimization indeed doesn't actually help.
- avidiax 2y agoIt resolves for me: com.fritz.box. 3514 IN AAAA 2001:19f0:6c00:1b0e:5400:4ff:fecd:7828 com.fritz.box. 3600 IN A 45.76.93.104
- mmcnl 2y agoYes, on Windows at least. As far as I know, Linux and macOS only use the DNS suffix for domains without a dot in the domain.
- jiveturkey 2y agono, not every request. only those that don’t exceed `ndots` number of dots, typically 1 for unix like OSes. so google.com will not have fritz.box appended
- mmcnl 2y agoThis is not true for Windows unfortunately. Even a lookup for google.com will have fritz.box appended. I added a screenshot to the article for clarity.
- TillE 2y agoI don't get that on Windows 11, with a FRITZ!Box that's mostly using the default settings. Server: fritz.box Address: fd00::[etc] Non-authoritative answer: Name: google.com Addresses: 2a00:1450:4001:80b::200e 172.217.19.78
- cellardweller 2y agoCan confirm, fritz.box only gets suffixed for names on the local network, which my Fritzbox 7490 is the authoritative name server for.
- mmcnl 2y agoThat's interesting.
- tetha 2y agoJust checked, systemd-resolved doesn't even support that behavior anymore[1], so any multi-label FQDN will get resolved without appending the search domain. So that's still a mess, but no mess of "rip apart the entire home network right now". 1: https://www.freedesktop.org/software/systemd/man/latest/systemd-resolved.service.html#Compatibility%20with%20the%20traditional%20glibc%20stub%20resolver https://www.freedesktop.org/software/systemd/man/latest/syst...
- namaria 2y agoYeah just sounds like a series of horrible decisions. Hardcode appending a suffix to every DNS request and then not securing the tld? What the shit?
- throwanem 2y agoI'd guess it was a decision made a long time before gTLDs came into vogue, maybe a very long time before. If there's a list of falsehoods programmers believe(d) about DNS, "that TLD will never ever resolve, not ever" should be somewhere near the top.
- jeroenhd 2y ago> that TLD will never ever resolve, not ever There are domains that will never be sold, but none of them are very sexy. RFC2606+RFC6761 list .example, .invalid, .localhost, and .test, but none of those are practical and some come with certain behavioural expectations. There's .home.arpa as well (RFC8375), which may be the most technically correct TLD to use for these domains, but also is one of the least marketable ones. Then there are the IDN test TLDs (إختبار, آزمایشی, 测试, 測試, испытание, परीक्षा, δοκιμή, 테스트, טעסט, テスト, பரிட்சை, let's hope my browser+HN did the RTL mixing right) that also probably won't resolve, but most users probably won't be able to enter any of those websites. AVM could've offered mDNS (if they don't already) and just use .local.