3 ms·
Isn't it controlled by whoever is running the .arpa domain?
by xxyyxyxyy 14y ago
Isn't it controlled by whoever is running the .arpa domain?
- ChuckMcM 14y agoYes and no. There is nothing [1] preventing any DNS server from responding authoritatively to a request that it is presented with, except a moral correctness to the protocol. [1] If you ever wondered how openDNS or your ISP sends you spammy web pages when you try to resolve something that doesn't exist, or how the hotel hijacks your browser into giving you a login page, this is it. You look for google.com it notes you haven't logged in and returns the address for its paywall as the answer. Oh except if you are running dnssec in which case it is a lot harder to lie about what you are authoritative for. But on my dns servers at home they all think they are authoritative for 10.in-addr.arpa. so that they will answer queries for that network.
- xxyyxyxyy 14y agoIs this to say what matters in terms of the response you get is which DNS server you query? And consequently whoever controls that server? You run your own .arpa zone for 10. So you control the PTR responses for 10.0.0.1 that are directed to your home DNS server? Isn't it true that anyone can download a copy of .arpa zone for the public address space? You could load this into your .arpa zone on your home DNS server. Couldn't you shave off a few queries out to the internet for each PTR lookup that way? Running a home DNS server sounds like a smart idea. You say "nothing is to stop...", and due to the "rules" allowing out-of-bailiwick delegations that's true (and also a source of some annoying side effects: cache poisoning, extra queries if glue is ignored, etc.), but what if you designed a DNS server to only query authoritative servers? Then getting the right response would become just a matter of selecting the proper authoritative server from a list, verifying you are actually connecting to that server and then securing the connection from tampering, right? DNSSEC wouldn't address those needs, would it? Anyway, running your own DNS server sounds like a smart idea. No spammy web pages like OpenDNS? Do you connect to your home DNS server while you're staying at hotels to avoid paywalls? If these devices were not crippled maybe you could travel with a good /etc/hosts file with all your important websites listed.