9 ms·
DNS piracy blocking orders: Google, Cloudflare, and OpenDNS respond differently
- xeonmc 1y agoQuestion: why do courts hit DNS providers instead of domain registrars?
- gruez 1y agoEasier to get jurisdiction over them. Google and Cloudflare has datacenters all over Europe. Meanwhile for the ivesoccer.sx domain, the registry is located in Sint Maarten and the registrar is a Danish company.
- thenthenthen 1y agoThe internet is really not that different from shipping companies. Maybe some insights there?
- natebc 1y agoYou're on to something here. They are fighting pirates too!
- TZubiri 1y agoInteresting. But dns registrars don't operate in the importing country. E.g: the .com registry is operated by verisign is in US Jurisdiction. If I wanted to block a website in Argentina it wouldn't make sense to ask Verisign to delete a website, I would ask the court to order a dns block to local ISPs registered as local companies
- Bender 1y agoQuestion: why do courts hit DNS providers instead of domain registrars? Most of the eggs are in one basket. Same as trying to get individual ISP's to censor something, reaching out to each of the hundreds of registrars is time consuming and prone to being ignored depending on the country. If on the other hand a government can get cooperation from even 3 of the biggest "free" resolvers then its a big win for them. It's also easier to monitor people when they choose to use corporate resolvers like Cloudflare, Google, OpenDNS, etc...
- nackerhewz 1y agoOnce the practice is well established they'll extend it to political opposition, independent journalism, inconvenient science, etc.
- gruez 1y agoShouldn't countries have the right to control activities inside their borders? The order was approved by the courts, so insofar as due process and checks and balances go, this seems fine. This is no different than any other sort of injunction or court order. What should be the alternative? That the internet should be some sort of lawless wild west? Opposing this on the basis of "they'll extend it to political opposition ..." makes as much sense as opposing the arrest of criminals because "they'll extend it to political opposition ...".
- logicchains 1y agoThe alternative is the belief that humans have some fundamental rights that it's unjust for governments to violate (e.g. the right to private, encrypted communication), and designing systems to make it as hard as possible for governments to violate those rights.
- gruez 1y ago>The alternative is the belief that humans have some fundamental rights that it's unjust for governments to violate (e.g. the right to private, encrypted communication) In what country is there actually a "right to private, encrypted communication"? At best there's rights for "privacy", which is a pretty woolly concept, but generally don't cover copyright infringement. More to the point, unless you reject the concept of copyright entirely, you have to accept that free speech rights will have to be "violated" to enforce it.
- saurik 1y agoOne can believe that something should exist even if it does not.
- codedokode 1y agoI read that using pirated sites is ok if you do it for learning. Why do courts block them if they have legal uses?
- gruez 1y ago>I read that using pirated sites is ok if you do it for learning 1. I don't think anyone has been prosecuted for accessing/using pirated materials. The people who have been prosecuted for torrenting were liable because torrent clients also upload, thereby making them go beyond merely accessing/using. 2. Claiming that those sites (ie. live soccer streams) is "learning" is a stretch. Moreover no such "learning" exemption exists, at least in the US. The closest you have is fair use, which has a 4 part test. "Learning" is one of the tests, but isn't a sole determinant. Photocopying textbooks wholesale is obviously illegal, even if it's for "learning".
- subscribed 1y agoNb: open source torrent clients can be patched so they will never ever upload even a single bit of data. I know it flies in the face of how the bittorrent protocol should operate, but there's a technical possibility. Another is using so called "seedbox" in the safe country, or torrenting only via vpn.
- yard2010 1y agoAaron Swartz is gone for less :'(
- AnthonyMouse 1y ago> The people who have been prosecuted for torrenting were liable because torrent clients also upload, thereby making them go beyond merely accessing/using. It's not clear why this would be a relevant distinction. If the use in question is fair use then copying is permitted. Why wouldn't this be the case for the person uploading the data as well as the person downloading it? Suppose you have a physical copy of a book and your friend wants a copy of a page for a use which is indisputably fair use, so you make a copy for them and give it to them for that purpose. How is that any different? > Claiming that those sites (ie. live soccer streams) is "learning" is a stretch. Wouldn't that depend on what the user is actually doing with it? If you're just watching the game with your friends, presumably not. If you're doing scientific research on sporting events and you need to run the video of every sporting event in the last 10 years through a computer for your study, maybe it is.
- udev4096 1y agoMost people use a self hosted recursive resolver, which makes blocking a public resolver pointless
- josephcsible 1y ago"Most people" certainly do not.
- pixl97 1y agoAlmost nobody is the better answer. Most people use whatever their ISP, phone, or browser provides.
- madeofpalk 1y agoIs the ISP-provided router a self-hosted recursive DNS server?
- pixl97 1y agoNo, via dhcp it points at the ISPs caching servers.
- Yeri 1y agoWell, I'm doing that, and in this case, Cloudflare 'protects' the website and blocks it (based on my Belgian IP). So no matter what DNS I use, it see "Unavailable For Legal Reasons".
- pixl97 1y agoHence why VPNs are also necessary.
- alabastervlog 1y agoWhat’s the DNS equivalent of using Yandex for search?
- miyuru 1y agoI think you are looking might be https://dns.yandex.com/ https://dns.yandex.com/
- tux1968 1y agoThat's brilliant. Thanks for the link.
- LargoLasskhyfv 1y agoHrm. Depending on your location, needs, and preferences, this might shine and sparkle even more brightly: https://mullvad.net/en/help/dns-over-https-and-dns-over-tls https://mullvad.net/en/help/dns-over-https-and-dns-over-tls
- subscribed 1y agoQuad9, OpenDNS. I can recommend both. Take a look here for a good start: https://www.techradar.com/news/best-dns-server https://www.techradar.com/news/best-dns-server
- mqus 1y agoregarding OpenDNS (from the article): > When OpenDNS was first ordered to block pirate sites in France, the company made a simple but drastic decision to leave the country entirely, effectively affecting all French users. Last week, it repeated this response in Belgium following a similar court order.
- devwastaken 1y agowhich means opendns is a non solution and should not be used.
- Dwedit 1y agoA screenshot shows an "Error 451" page, but how can that even happen? It's https. Unless Cloudflare is also the web host, they can't change a page like that without the client seeing a certificate error.
- gruez 1y agoIt is. Non-authoritative answer: ivesoccer.sx nameserver = lou.ns.cloudflare.com ivesoccer.sx nameserver = venus.ns.cloudflare.com
- deleted 1y ago[deleted]
- oskapt 1y agoIt’s DNS so they just have to accept the query and redirect it to a local server that answers for anything and returns the 451 error. However, it’s also worth noting that Cloudflare is a giant MitM proxy who already decrypts everything and retransmits it. No communication with any domain fronted by Cloudflare is secure.
- belter 1y agoYes...Oh the good times... "Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752 https://news.ycombinator.com/item?id=13718752
- Andoryuuta 1y agoIn order to function, CDNs have to act essentially as giant opt-in MITM services. When you setup a CDN in front of your site, you will either need to give them your cert, or let them issue a cert (e.g. via let's encrypt). If they can serve your site with https normally, they can serve any content they want under it.
- jsheard 1y agoThis is about CFs public DNS resolver though, and not every domain they're ordered to stop resolving will also happen to be served though their own CDN. In this case it was, which explains how they're able to serve a 451 error over HTTPS, but that won't always be the case as the article implies. In some other cases I suppose they could downgrade the connection to HTTP in order to show their 451 page, but if the domain is HSTS'ed then that wouldn't work either. That'd have to just black-hole the query like Google does.
- deleted 1y ago[deleted]
- aboringusername 1y agoIt's very clear that DNS is fundamentally broken and any resolver that does not resolve because of political decisions should be considered not fit for purpose; it is advised not to use any resolver that is mentioned in this article as they have all been affected. My understanding is DNS resolves a domain to an IP address. If there is any process that prohibits that, then it's not working by design. Thankfully there are many resolvers that will always resolve no matter what 'legal' may throw at it. This is fundamental despite what content lies on the other side. There will always be cat and mouse with speech and rights to access, and any protocols will be challenged. Thankfully, others will say 'no thank you' and refuse to listen to any order, legal or otherwise. And thankfully, they cannot be touched (VPNs, TOR et al). Even the most censorship heavy countries in the world have to resort to physically shutting the internet down, because if there is a pathway, it will be found. It's just human nature.
- TZubiri 1y ago[flagged]
- Novosell 1y agoMan, that's is some hardcore "think of the children" bullshit. Things which protect people will inadvertently also end up protecting some bad people. The only solution to that is killing all humans.
- userbinator 1y agoI don't know if the comment you're replying to is actually satire.
- TZubiri 1y agoSimilarly, there are laws for subpoenas in banking. If you wire wire 100k to some random account, courts can ask who you wired to. This, again, is used to prevent crime. It is the system we have whether you like it or not. You can implemet ridiculous amounts of encryption such that providers not only can't see the contents, but also can't see headers or where info is being sent to. But those technologies are munitions providers that sell that are enemies of the law.
- exiguus 1y agoWao. Thanks for the research on this. This is one reason, beside some others, to run your own recursor.
- mschuster91 1y ago> When OpenDNS was first ordered to block pirate sites in France, the company made a simple but drastic decision to leave the country entirely, effectively affecting all French users. Last week, it repeated this response in Belgium following a similar court order. Who would have thought that Cisco would be on the side of the good guys for once?! As for Cloudflare, what they do is scary. The screenshot clearly shows a valid HTTPS certificate, so either they don't do DNS blocking but instead implement the block on their loadbalancer side or they mis-issue HTTPS certificates. The former is only possible when the target site is also served by Cloudflare (which leaves the question what Cloudflare does for domains that are targetted by a court order but not using Cloudflare loadbalancing), the latter would be a serious breach of how HTTPS certificates should be issued. And in the end I believe that courts need to be educated on how the Internet works. Companies should not be allowed to target DNS, they should be forced to target the actual entities doing the infringement - and if the target isn't in the scope of Western jurisdictions (that have various legal-assistance treaties), it's either tough luck (e.g. if the pirates are in Russia, China or other hostile nations) or they should get their respective government involved to use diplomatic means.
- eddythompson80 1y agoNot really sure what you find scare about that. If you set cloudflare as your dns provider, they own the dns response they give you. If they get court ordered to redirect you to a site saying this is illegal. Is your preference for this to be over plaintext? Cloudflare is a public CA. Your browser or OS trusts it implicitly. If you don’t trust Cloudflare, remove it from that list I guess.
- lokar 1y agoThey have a trusted CA root subject to strict policy rules that I’m pretty sure don’t allow this.
- ycombinatrix 1y agoCAs are well known for being lazy & incompetent. Look at how much bullshit we tolerate from just Entrust: https://wiki.mozilla.org/CA/Entrust_Issues https://wiki.mozilla.org/CA/Entrust_Issues
- zerof1l 1y agoEveryone should just start running their own authoritative DNS servers like Unbound. That will eliminate the issue. And why is it still the norm that all major OSes don't ship with authoritative DNS... Same with all consumer routers. It is not an option at all, or if you run OpenWRT, you'd have to manually set it up. Hopefully, there will be some change in that direction.
- ratatoskrt 1y agoIf I set up my own authoritative DNS servers, can I still use DNS over TLS or DNS over HTTPS?
- Aachen 1y agoSure you can run TLS/HTTPS to your own server or to localhost if you want to keep private from the intervening systems that you are querying for a certain domain
- kdmtctl 1y agoIf you set your own authoritative DNS, you could use it only for your zones. To use DoH, etc for the whole traffic, you need a recursive server. Unbound is a recursive server with some rudimentary authoritative extensions.
- kdmtctl 1y agoIt will help with spoofing but will not protect from eavesdropping. Most of the times cloudflare is a least dangerous adversary.
- alabastervlog 1y agoI would be shocked it they’re not taking money to let US TLAs back-door them.
- kdmtctl 1y agoThat will ruin the stocks. No need to use back doors, court order is pretty easy to get especially if the site in question is true malicious.
- rustcleaner 1y agoMaybe we'll get smart and just install Hyphanet (Freenet). Only thing it needs done to be perfect (imo) is to duplicate the opennet code, make it all TCP only, and swap every IP address field for a .onion address field, and call this new opennet onionnet. He who has the key gets the file anonymously!
- ls612 1y agoChina showed that the Great Firewall was possible. The rest of the world is now following and nothing anyone on this board says or does can change that. Such is the true nature of power.
- fitblipper 1y agoIt seems like a centralized authority for DNS that must answer to some government is prone to censorship. Would moving domain registration into a public Blockchain allow for a more resilient and democratized internet?
- Hikikomori 1y agoIf something doesn't work, fix it with Blockchain.
- ycombinatrix 1y agoidk, i think it would be cool to have a copy of every dns record on my hard drive
- pests 1y agoYou can do that already now.
- DanAtC 1y agoKind of. You can get the nameservers (and glue records if available) for every domain under a TLD if the TLD makes their zone file available. See https://github.com/jschauma/tld-zoneinfo https://github.com/jschauma/tld-zoneinfo
- ycombinatrix 1y agoWell kinda but that would be an incomplete snapshot. Versus a blockchain where every DNS record change is necessarily written into my copy. IPNS is similar project that already exists.
- rainsford 1y agoAs the old regex joke goes, "now you have two problems".
- Bender 1y agomore resilient and democratized internet If you only said more democratized I might lean towards yes with some caveats but you included resilient and DNS is not just peoples workstations and cell phones. It is used by very big and complex systems that make vast numbers of changes every second. Trying to force all of that through blockchain would require a complete re-thinking of how blockchain and the internet work in my opinion. I would be happy to be proven wrong. Someone could try it but that someone would have to be a very big organization for any kind of canary test. The devil would be in the implementation details as to how this monster would scale and handle a myriad of failure scenarios. People would also need to be able to troubleshoot complex misconfigurations. It would take some serious battle hardening before a production revenue generating company would take a chance with it.
- cesarb 1y ago> Google’s response also appears to go against the advice of the Belgian court, which required the DNS providers to redirect users to a dedicated page, presumably to provide further detail. That advice made sense in the plain-text HTTP era, but it's not longer viable; attempting to do that nowadays would only lead to an "invalid certificate" error page. The only ones which can make that work are the site itself, or a CDN in front of it (which, as others have noted, often means cloudflare can do that, but not other DNS providers like google).
- 16V47uF 1y agoSpain laughs at those countries and just orders the ISPs to do SNI censoring.
- fowl2 1y agoSuprised no one has mentioned RFC 8914 Extended DNS Errors, specifically section 4.17[1]: > 4.17. Extended DNS Error Code 16 - Censored > The server is unable to respond to the request because the domain is on a blocklist due to an external requirement imposed by an entity other than the operator of the server resolving or forwarding the query. Note that how the imposed policy is applied is irrelevant (in-band DNS filtering, court order, etc.). Which would be relevant for Google DNS's "Query refused" at least. Although I guess it's possible maybe they do support it but Windows/Chromium don't... [1] https://www.rfc-editor.org/rfc/rfc8914.html#section-4.17 https://www.rfc-editor.org/rfc/rfc8914.html#section-4.17