9 ms·
DNS Provider Quad9 Sees Piracy Blocking Orders as "Existential Threat"
- MangoToupe 11mo agoI've increasingly taken the attitude that digital media is simply lost to corporate interests and there's nothing we can do about it aside from not spending money or time on the internet.
- ACCount37 11mo agoNo, "not spending money or time" is utterly worthless. It has zero leverage. Even if you could convince 1 person in 1000 to do that, you'd represent 0.1%. And that "1 in 1000" is hopelessly optimistic as it is. If you want to change the world, "individual action" should be at the very last place in your list of actions to take.
- anonym29 11mo ago>If you want to change the world, "individual action" should be at the very last place in your list of actions to take. The heliocentric model began with one person out of the entire population of earth having the courage to publicly, loudly, and assertively disagree with TPTB.
- iso1631 11mo agoPresuming you're talking Europe only, are you talking Copernicus? Brahe? Kepler? Galileo? You know that the heliocentric model had been discussed 2000 years earlier in Europe.
- cess11 11mo agoGuessing this might be interpreted by some as a reference to Galileo so I'll take the opportunity to mention Against Method. https://en.wikipedia.org/wiki/Against_Method https://en.wikipedia.org/wiki/Against_Method
- ACCount37 11mo agoLet's assume that correct. Now, what did that "one person" do? Just reject the idea of Earth being the center of the universe? Or actually seek ways to make an alternate model more accepted? "Individual action" is fucking worthless. But not all types of activism are.
- MangoToupe 11mo agoMy point was not about changing the world but having a pleasant consumer experience. My local library works just fine for just the cost of my tax dollars.
- Imustaskforhelp 11mo ago> “At what point does legal compliance become de facto censorship?” I genuinely agree with this statement a lot. Also another aspect of this is that the bigger companies can somehow "legally" do things which I don't think would work but they have so many resources to strech the court case for a long time. And the fact is that even after that, even if they are fined for some dollars. They are more than likely to just pay than try to actually fix the core issues which effects everyone harmfully except the company. All for profit smh. I sometimes wonder if there is a word for this phenomenon for how our system has gotten into such a rotten state from lobbying to this yet at the same time genuine non profits get existential threats for the same behaviour but they simply don't have the funds...
- gtsop 11mo ago> if there is a word for this phenomenon for how our system has gotten into such a rotten stat There is, it's the system's name: Capitalism Noone ever in the universe claimed that this system serves primarily the needs of humans. It serves profit. Now there is a ven diagram that has a union area between profits and needs, but the system does not care about making this union bigger, it cares about making the profits bigger. When that overlaps with needs... it is just a happy side effect.
- kannanvijayan 11mo agoI tend to agree with this sentiment, but my takeaway is slightly different. People who would describe themselves as supporters of "capitalism", as well as supporters of "communism" or "socialism", are not able to admit that their belief systems are actually religious in structure. Not spiritual perhaps, but effectively "secular religions". Both capitalism and its nemesis arose in the mid 1900s, when humanity was obsessed with modernist thinking about "solving problems once and for all". And in that context, the people fell in love with these two "clean systems". A more perfect set of rules. Sure, capitalism doesn't claim to be the most powerful god. But in surrogacy, it claims to be "the least imperfect system". Which is structurally the same claim: declaring the scripture to be some apex that is not surpassable. The main difference between communism and capitalism was how it was implemented. The USSR went full-tilt ideologically rigid, and collapsed very quickly. The US didn't go full-tilt capitalism. It implemented a hybrid system with a high marginal tax, welfare programs, subsidies, labour unions, public works projects, along with a market system, and that hybrid non-ideologically rigid model served it well. Around the time it was clear the USSR was collapsing, the USA went hard tilt in favour of ideological purity in capitalism. Systematic series of clawbacks in the tax regime, privatization, elimination of labour unions. As they leaned into the religion, it was used against them, much like the communist religion was used against the people of the USSR. And now they have been robbed of their prosperity, of the value of their efforts, much like the people in the USSR were robbed.
- soiax 11mo ago[flagged]
- flumpcakes 11mo agoGoing after DNS resolvers seems like the easy win. If a website was breaking the law so egregiously then take it to ICANN to get the domain name seized. I'd wager that's a much harder thing to prove, hence the strong arming of DNS resolvers.
- michaelt 11mo agoSeizing a domain name via ICANN has to be global, as I understand it, while a website might have only broken some nations laws. If the UK government wants to ban porn but loves gambling, while the US wants to ban gambling but loves porn, a blocking mechanism that lets them have different blocklists allows both nations to get the censorship their voters have chosen.
- whimsicalism 11mo agoPretty sure the US does it all the time or just contacts the registrar.
- iamnothere 11mo agoOnly for TLDs within legal reach. TLDs like .ru and .su require diplomatic outreach and backroom deals.
- dc396 11mo agoICANN has no mandate, mechanism, or ability to seize domains. The only tool they have is de-accreditation of registrars (which obviously affects ALL domains registered by that registrar) and that tool is only used when there is clear and non-cured breach of the ICANN Registrar Accreditation Agreement.
- BLKNSLVR 11mo agoWould the root DNS servers ever get modified or censored as a result of court action? My thoughts were that DNS-level censorship is essentially a dead end because the root servers are sacrosanct, and there will always be secondary DNS servers to query, who then use the root servers. Sucks for DNS providers in authoritarian countries though.
- Macha 11mo agoThe root DNS servers basically only tell you where the registry servers are, they don't contain records themselves. If someone censored a domain at the registry level then the root servers would be no help
- iamnothere 11mo agoThis is true but I can imagine where they might go after the lowest reachable branch of the tree, up to threatening to remove country-level TLDs from the root servers for noncompliance. Only the US really has the leverage to do this, and it would just fragment the internet, as additional root servers would pop up to serve the missing TLDs. So it’s unlikely but possible.
- dc396 11mo ago"Additional root servers" popping up that would server missing TLDs would fail DNSSEC validation unless you modified the root hints and turned off DNSSEC or resigned the root zone and updated the trust anchors in validating resolvers.
- iamnothere 11mo agoOh it would be chaos, but I’m sure there would be a workaround available within a week. Alternative roots already exist: https://en.wikipedia.org/wiki/Alternative_DNS_root https://en.wikipedia.org/wiki/Alternative_DNS_root
- lokar 11mo agoBut the query is of the whole name. In theory they could nxdomain blocked names. But long ttls and caches would mostly break this as an approach
- casey2 11mo ago[flagged]
- pbasista 11mo agoIf you would like to talk about piracy, please define it first. In my opinion it is unclear what you are referring to because many people have different views on what the term piracy actually means.
- sschueller 11mo agoYou mean like ChatGPT? Why is it ok for them to "pirate" the entire internet and not for a small individual. Maybe the whole copyright system is broken.
- notanastronaut 11mo ago>>Pirates need to wake up to the fact that they are harming creators and people who provide the services that make modern life possible. Could you clarify a single service that is being pirated that could be classified as "make modern life possible"? I'm just curious.
- fundatus 11mo agoMany ISPs in Germany have stopped fighting this fight as well and sadly have now even started to self-censor their DNS servers.[1] [1] https://cuii.info/en https://cuii.info/en
- dewey 11mo ago> have now even started This has been the case for a very long time. Back when TBP was popular this was already the case.
- iamnothere 11mo agoMore people should run their own recursive resolvers with unbound. There’s no need to rely on centralized DNS anymore.
- kavouras 11mo agoIsn't this putting unsustainable load on the root servers?(on the scenario that many people do that)
- seethishat 11mo agohttps://datatracker.ietf.org/doc/html/rfc8806 https://datatracker.ietf.org/doc/html/rfc8806 Abstract Some DNS recursive resolvers have longer-than-desired round-trip times to the closest DNS root server; those resolvers may have difficulty getting responses from the root servers, such as during a network attack. Some DNS recursive resolver operators want to prevent snooping by third parties of requests sent to DNS root servers. In both cases, resolvers can greatly decrease the round-trip time and prevent observation of requests by serving a copy of the full root zone on the same server, such as on a loopback address or in the resolver software. This document shows how to start and maintain such a copy of the root zone that does not cause problems for other users of the DNS, at the cost of adding some operational fragility for the operator. This document obsoletes RFC 7706.
- belorn 11mo agoIf we are talking about the actually root servers, there are 13 redundant names spread out (thanks to anycast) on around 1700 servers located around the world, and the lookup a user would do is cached for 2 days. That mean the highest amount of traffic a system will generate is one request per unique TLD (like .com) per 2 days, and it will fit a single UDP package. We can then do some guesses about size for questions like "what is the nameservers for .com". Those are a bit larger than most dns queries since the answer is a bit bigger than most, since .com has a lot of nameservers, so lets put it down to 800 bytes. Every 2 day a average use might then, using some guessing, generate maybe 10 kb of traffic, or about 0.015 seconds of watching a 1080p video on youtube.
- dengolius 11mo agoDoes anyone use Mullvad DNS servers? https://mullvad.net/en/help/dns-over-https-and-dns-over-tls#specifications https://mullvad.net/en/help/dns-over-https-and-dns-over-tls#... I found them more acceptable.
- b3lvedere 11mo agoDidn't know they have publicly available DNS servers. Thanks. I've also started using/testing the DNS4EU servers: https://www.joindns4.eu/ https://www.joindns4.eu/
- Tadpole9181 11mo agoI have had nothing but problems with their DNS service. Outages what feels like a daily basis. But the VPN itself is great!
- kristofferR 11mo agoThey're pretty slow for me, 350ms on average: https://i.imgur.com/7CeydnY.png https://i.imgur.com/7CeydnY.png
- dengolius 11mo agohttps://dns10.quad9.net/dns-query https://dns10.quad9.net/dns-query Unsecured: No Malware blocking, no DNSSEC validation (for experts only!) Maybe it is fast because it is not secured at all? :D
- dengolius 11mo agohttps://dnsspeedtest.online/ https://dnsspeedtest.online/ a link with benchmarks for newer readers
- LeoPanthera 11mo agoI do (as a fallback), but they're extremely slow. Did you know Wikimedia also runs a public DNS service? https://meta.wikimedia.org/wiki/Wikimedia_DNS https://meta.wikimedia.org/wiki/Wikimedia_DNS
- 0xbadcafebee 11mo agoRe: "Cisco has decided to leave france": (https://web.archive.org/web/20250614052849/https://support.opendns.com/hc/en-us/articles/27951404269204-OpenDNS-Service-Not-Available-To-Users-In-France-and-Portugal https://web.archive.org/web/20250614052849/https://support.o...) Effective June 28, 2024: Due to a court order in France issued under Article L.333-10 of the French Sport code and a court order in Portugal issued under Article 210-G(3) of the Portuguese Copyright Code, the OpenDNS service is not currently available to users in France and certain French territories and in Portugal. We apologize for the inconvenience. July 23, 2024: Cisco's OpenDNS service has been reactivated in Portugal and is currently available following a decision by the Lisbon Court of Appeal. It's laudable that Quad9 want to fight censorship, but they too could block French requests in this way. Maybe redirect to an HTTP/HTTPS IP that tells users about the issue and gives them contacts to their government representatives?
- sudopsuedo 11mo ago> Other companies, such as Google and Cloudflare, have the technical means to restrict the blockades to France, but not all providers can do so easily. That includes Quad9, which had no other choice than to apply the French blocking request worldwide. Just quoting the article, can anyone weigh in on the costs/complexity of a public DNS resolver implementing geo-fencing?
- 0xbadcafebee 11mo agoThere are multiple free and paid geoip databases, from $0 to $1000 a year, depending. Then an hour to write a script to add iptables rules from the database for the country of choice. (Example: https://gist.github.com/asheroto/934e056a302adda334077f0c85cfe4b4 https://gist.github.com/asheroto/934e056a302adda334077f0c85c...) I don't know what is unique about Quad9 that they couldn't do this, but it's possible they have some technical limitation
- strictnein 11mo agoThere's likely a performance impact that is significant at that scale. If they're blocking 670M DNS requests a day, they're likely doing 10-100x that overall. Have you implemented something at that scale to say this is no big deal for them to do? And what about when 180 countries want their own list and maybe even states, providences, etc do as well?
- sschueller 11mo agoThis is also why it is important for Switzerland to not sign the deal with the EU next year. The 8k+ page deal would also require Switzerland to pull the line with EU regulation regarding copyright. The freedom we have right now to download would fall away. Doesn't matter if you are left or right, the deal is bad for all of us.
- Havoc 11mo agoAnother side effect of law makers yoloing legislation on things they don’t seem to understand
- styanax 11mo agoHoping the HN DNS savvy reading this can help me understand a Quad9 thing I ran into. I was debugging (as in scratching my head) a bank website login problem and ended up doing some DNS checks against their domain, usual stuff, while using Quad9 as my DNS provider. While testing, I was using Google and Cloudflare as well, and started noticing something - Quad9 does not return all A records listed for a domain, the same way Google/Cloudflare do. dig -t A google.com @8.8.8.8 +short (6x IPs) dig -t A google.com @1.1.1.1 +short (6x IPs) dig -t A google.com @9.9.9.9 +short (1x IP) This gave me a weird feeling; I get there's a lot of DNS geo magic and 8.8/1.1 serve 2 different subnets, and 9.9 a third. But... where did the other 5 expected IPs from Quad9 get off to?
- tom1337 11mo agointerestingly, i only get one IP from each command: $ dig -t A google.com @8.8.8.8 +short 142.250.184.206 $ dig -t A google.com @1.1.1.1 +short 216.58.206.46 $ dig -t A google.com @9.9.9.9 +short 142.250.185.238
- styanax 11mo agoI'm sure geo has something to do with it - my connections generally terminate in Austin, TX but it varies around Central US. I have T-Mobile Home Internet and our IPs show up to remotes under the same general ASNs as the traditional mobile network (big huge CGNAT, my IP can change 5 times a day or whatnot and it doesn't reflect where I actually am located). Edit: in case useful to someone reading, right now I have an IP assigned out of this block: NetRange: 172.32.0.0 - 172.63.255.255 CIDR: 172.32.0.0/11 NetName: TMO9 NetHandle: NET-172-32-0-0-1 Edit edit: in the network record is a link to the self-reported geo data, I missed that. Comment: Geofeed https://raw.githubusercontent.com/tmobile/tmus-geofeed/main/tmus-geo-ip.txt
- toast0 11mo agoIf you're behind a big CGNAT and Google knows it, they might intentionally return multiple addresses to have more capacity. Each service port (IP:Port) can only receive 64k connections from each NAT IP, returning more IPs from DNS makes more connections available. Google is a very popular service, so it makes sense to do. (Less so for v6, though) Alternately, if they can't get a good feel for where you are, returning A records for multiple locations makes sense, too. No idea why 4 AAAA vs 6 A; Google runs dual stacked and I'd expect the same number of records for both; IIRC, 8 AAAA will usually fit in a 512 byte udp reply, and anyway DNS64 might expand As into AAAAs, so you have to gauge sizes with those anyway.
- seethishat 11mo agoThis all started, in earnest, with Response Policy Zones being added to BIND. RPZ allow DNS resolvers to lie to clients by returning (nxdomain or redirects to other domains) and the client does not know it is being lied to. https://www.isc.org/docs/BIND_RPZ.pdf At first, RPZ was used to block known malicious domains (drive by malware downloads, etc.). Then, the security weenies started using RPZ to block other things like TikTok (for administrative/legal reasons). That's when the DNS became a big lie. I guess some day, one political party will use it to block the websites of other political parties, etc. That's stupid to say (I know) but that seems to be the slippery slope we are sliding down.
- mzajc 11mo agoDoes Quad9 run a resolver with DNSSEC but without "malware" blocking? So far I've had multiple instances (twice for a torrent tracker, once for gist.github.com) where they blocked a non-malware domain for a short while, which is really annoying to deal with.
- input_sh 11mo agoUnfortunately no, they run 9.9.9.10, which is without "malware" blocking and without DNSSEC.
- estimator7292 11mo agoKind of wild that we're approaching a decentralized internet not for the virtue of decentralization, but because of insane authoritarian censorship.
- qqvga 11mo agoironically/appropriately[?] a virtue of decentralization would be combatting insane authoritarian censorship
- jMyles 11mo ago> insane authoritarian censorship Sanity, liberty, and censorship-resistance are virtues. (before mental wellness people get up in my grill, by "sanity", I mean the preconditions likely to make sanity widespread)
- xboxnolifes 11mo agoI consider conser resistance the defining virtue of decentralization.
- BikiniPrince 11mo agoI just run my own name server. DNS blocking is no longer an issue unless they get to the root name servers. With a little domain warming from the top 5000 domains it’s pretty snappy most of the time.
- lokar 11mo agoOr block outbound 53 on residential networks
- polski-g 11mo agoComcast wonderfully intercepts port 53 traffic and shunts it to their own servers. I was getting an A record for sending I knew didn't exist. Spent quite a bit of time investigating until I just tried opening the site up in a browser. Then I saw their lovely as page. Thanks guys...
- allset_ 11mo agoDNS literally would not work if they did that.
- JdeBP 11mo agoMore realistically, DNS blocking is no longer an issue unless "they" get to the registries for the top-level/second-level domains. It's easy to make yourself immune to things injected by the root content DNS servers, with at least two mechanisms for combatting this (the better one being just running your own private root content DNS server) having existed for most of this century.
- mlhpdx 11mo agoAre we heading to a place where there will be many DNS resolvers just to get a "full" picture of the internet? Or perhaps topical upstream resolvers?
- charcircuit 11mo agoif (geoip[sourceIp] === "France") { if (geoblocks["France"][sourceIp]) { return NOT_FOUND; } } I don't think the cost of writing the above code is an existential threat.
- wiredpancake 11mo ago[dead]