4 ms·
Everyone should just start running their own authoritative DNS servers like Unbound. That will eliminate the issue. And why is it still the norm that all major
by zerof1l 1y ago
Everyone should just start running their own authoritative DNS servers like Unbound. That will eliminate the issue.
And why is it still the norm that all major OSes don't ship with authoritative DNS... Same with all consumer routers. It is not an option at all, or if you run OpenWRT, you'd have to manually set it up.
Hopefully, there will be some change in that direction.
- ratatoskrt 1y agoIf I set up my own authoritative DNS servers, can I still use DNS over TLS or DNS over HTTPS?
- Aachen 1y agoSure you can run TLS/HTTPS to your own server or to localhost if you want to keep private from the intervening systems that you are querying for a certain domain
- kdmtctl 1y agoIf you set your own authoritative DNS, you could use it only for your zones. To use DoH, etc for the whole traffic, you need a recursive server. Unbound is a recursive server with some rudimentary authoritative extensions.
- kdmtctl 1y agoIt will help with spoofing but will not protect from eavesdropping. Most of the times cloudflare is a least dangerous adversary.
- alabastervlog 1y agoI would be shocked it they’re not taking money to let US TLAs back-door them.
- kdmtctl 1y agoThat will ruin the stocks. No need to use back doors, court order is pretty easy to get especially if the site in question is true malicious.
- NoahKAndrews 1y agoOPNsense defaults to Unbound
- rayhaanj 1y agoI think you mean "running your own recursive resolver", an authoritative server is one which is authoritative for some zone (e.g. example.net), whilst a recursive resolver is one that goes and walks from the root of the DNS hierarchy to the leaf that you have queried. It is probably quite a bit slower though needing to have roundtrips at each stage of the resolution, which is also likely a reason that these public resolvers get so much use (latency improvement via caching).
- belorn 1y ago> It is probably quite a bit slower though needing to have roundtrips at each stage of the resolution The average load time for a website is 2.5 seconds. The added load time from running your own recursive resolver, which is only added the first time the site is loaded, would be around 50ms, or 2% increase load time. DNS resolving is not a major aspect of a typical websites load time. If you want to speed things up, run a local proxy which local cached version of all popular web frameworks and fonts, and have it be be constantly populated by a script running in the background. That will save you much more than 2% on first load.
- rayhaanj 1y agoI just did some measurements and am impressed on both fronts: DNS recursive resolution is faster than I anticipated, but also page load times for well optimised sites are also very fast (sub 0.5s). Here's some data: Recursively resolve bbc.com: 18ms https://pastebin.com/d94f1Z7P https://pastebin.com/d94f1Z7P Recursively resolve ethz.ch: 17ms https://pastebin.com/x6jSHgDn https://pastebin.com/x6jSHgDn Recursively resolve admin.ch: 39ms: https://pastebin.com/DUTg8Rit https://pastebin.com/DUTg8Rit Page load in Firefox: bbc.com DOMContentLoaded: ~40ms, page loaded: ~300ms reuters.com DOMContentLoaded: ~200ms, page loaded: ~300ms google.com DOMContentLoaded: ~160ms, page loaded: ~290ms So it's quite reasonable to do full recursive resolution, and you'll still benefit from caching after the first time it's loaded. One other idea I had but never looked into it was instead of throwing out entries after TTL expiry to just refresh it and keep it cached, no idea if BIND/Unbound can do that but you can probably build something with https://github.com/hickory-dns/hickory-dns https://github.com/hickory-dns/hickory-dns to achieve that.
- VoodooJuJu 1y ago[dead]
- znpy 1y agoI do run my bind in my lan (and in my vpn, serving a private zone) and i’m only occasionally reminded about dns blocking issues by articles like this. Needless to say, the bar is way lower. Anybody willing to pirate stuff can easily change their dns to any public dns service and access any website. You don’t even need a vpn.
- cesarb 1y ago> Everyone should just start running their own authoritative DNS servers like Unbound. I used to do that, but it caused some odd issues at my former ISP, which I suspect were due to connection tracking state table exhaustion on their CGNAT box; running your own recursive server means a lot of UDP connections, and unlike with TCP, there's no well-defined point at which the connection tracking state can be released, which can lead to it accumulating. Making unbound use DoT to cloudflare made things much more stable (since DoT uses TCP, the connection tracking state can be released immediately when each connection is closed).
- csense 1y agoIf Alice runs her own DNS server, where does she get the information "example.com resolves to 10.23.45.6"? At some point Alice will have to ask someone else -- Bob, let us say -- and Bob won't give her that information if he's been court-ordered not to. I don't think traditional DNS can work if your adversary can get court orders [1]. You need some sort of decentralized solution that's hard to block even with court orders, e.g. Namecoin or ENS. [1] Is evading a court order a legitimate objective? Most people would say "no" but the Internet functions in all countries, including repressive ones. Even in the US, it's not entirely inconceivable the Trump administration could make an executive order to require DNS providers to block certain websites he doesn't like (perhaps using post-9/11 powers granted to the executive branch to fight terrorists, that never got revoked even though Osama bin Laden is dead and the wars in Afghanistan and Iraq are over). The US has strong protections on freedom of speech, but working through the courts takes time, and becomes difficult when someone says the magic words "national security".