4 ms·
regarding OpenDNS (from the article): > When OpenDNS was first ordered to block pirate sites in France, the company made a simple but drastic decision to leave
by mqus 1y ago
regarding OpenDNS (from the article):
> When OpenDNS was first ordered to block pirate sites in France, the company made a simple but drastic decision to leave the country entirely, effectively affecting all French users. Last week, it repeated this response in Belgium following a similar court order.
- devwastaken 1y agowhich means opendns is a non solution and should not be used.
- pixl97 1y agoThe problem is we don't need a few big providers, we need thousands of smaller ones everywhere. Big providers are easy to attack with a single bullet (court case).
- ratorx 1y agoSmall providers can also be hit with the same bullet (depending on the wording), it’s whether the laws can actually be enforced, which is a cat-and-mouse game the same way piracy generally is. They are still providing a digital service in the country and are subject to the laws.
- pixl97 1y agoSmall providers can, but when they are across many countries it takes a lot of work to actually accomplish that.
- kaoD 1y agoDNS feels like it should be easy to proxy. Or just have more distributed resolvers. Why isn't it done more? Is it super expensive? Maybe due to UDP allowing traffic-amplification attacks?
- ycombinatrix 1y agoWhat do you mean by "DNS proxy"? What is a DNS resolver if not a proxy for DNS requests?
- kaoD 1y ago> What is a DNS resolver if not a proxy for DNS requests? A DNS resolver... resolves (recursively). unbound[0] would be an example. A proxy instead only forwards to a trusted DNS server (or servers) and may cache their responses but won't do any resolution by themselves. dnsmasq[1] would be an example. My guess is a simple proxy is less vulnerable to UDP amplification attacks (and also vastly simpler to implement and maintain). The drawback is you need a resolver you trust, but that might be okay if you actually do have one. E.g. some DNS server that you know is safe but is not operating in your country (you might just want to proxy it so its closer to you for lower latency). [0] https://en.m.wikipedia.org/wiki/Unbound_(DNS_server) https://en.m.wikipedia.org/wiki/Unbound_(DNS_server) [1] https://en.m.wikipedia.org/wiki/Dnsmasq https://en.m.wikipedia.org/wiki/Dnsmasq
- ycombinatrix 1y agothat's true! i was thinking about it in terms of resolv.conf, where everything is a resolving "nameserver" with an ip address regardless of how it actually works. In that sense, proxies are also resolvers. Just not recursive.
- tmtvl 1y agoNo, it means that the French and Belgian governments are pieces of shit who should be lynched.
- ycombinatrix 1y agoHow exactly do they "leave the country"? Do they start blocking French & Belgian IPs?
- betaby 1y agoThat's how: $ dig kernel.org @208.67.220.220 ; <<>> DiG 9.18.33-1~deb12u2-Debian <<>> kernel.org @208.67.220.220 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 12644 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 2 ;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 1410 ; EDE: 16 (Censored) ;; QUESTION SECTION: ;kernel.org. IN A ;; ADDITIONAL SECTION: kernel.org. 0 IN TXT "The OpenDNS service is currently unavailable in France and some French territories due to a court order under Article L.333-10 of the French Sport Code. See https://support.opendns.com/hc/en-us https://support.opendns.com/hc/en-us" ;; Query time: 8 msec ;; SERVER: 208.67.220.220#53(208.67.220.220) (UDP) ;; WHEN: Sun May 11 22:56:23 UTC 2025