4 ms·
Old bug fixed in 2020. OP didn’t know of the fix it seems. Was covered on Hacker News at the time. Still top google result.
by ectospheno 2y ago
Old bug fixed in 2020. OP didn’t know of the fix it seems. Was covered on Hacker News at the time. Still top google result.
- deathanatos 2y agoWell that's horrifying. For those that are wondering like me: https://blog.apnic.net/2020/08/21/chromiums-impact-on-root-dns-traffic/ https://blog.apnic.net/2020/08/21/chromiums-impact-on-root-d... Essentially, it generated 3 random, single-label (so, "TLD") queries, and ran them through DNS. Whatever recurser that lands at obviously wouldn't have random junk in its cache (unlike probably any other root record) and thus had to go to the root servers for it. They did this to try to not display an omnibox result for single words (the example in the article is "marketing") on what I'm going to just call "broken networks"; see TFA if you're curious.
- bewaretheirs 2y agoNote that running your own mirror of the root on the recursive nameserver(s) on your network will keep the traffic generated from these sorts of queries off the rest of the internet. If you're already running your own recursive resolver on reasonably up-to-date software it can be surprisingly easy to set this up; see rfc8806 for some config examples.
- lyu07282 2y agoIs there a use case for that? I mean other than that it's kinda cool
- bewaretheirs 2y agoPer rfc8806, because the data in the root zone has long TTL values, most queries to the root servers are for nonexistent top-level domains due to typos and search paths gone wrong, so in some sense it's community service to reduce useless traffic to the roots -- you do a single burst download of about 2MB daily instead of all of your query traffic. Other reasons why you might do it are covered in rfc8806 - slightly reduced latency on cold-cache DNS queries, added resilience against DoS attacks against root DNS servers.