4 ms·
Many ISPs in Germany have stopped fighting this fight as well and sadly have now even started to self-censor their DNS servers.[1] [1] https://cuii.info/en htt
by fundatus 11mo ago
Many ISPs in Germany have stopped fighting this fight as well and sadly have now even started to self-censor their DNS servers.[1]
[1] https://cuii.info/en https://cuii.info/en
- dewey 11mo ago> have now even started This has been the case for a very long time. Back when TBP was popular this was already the case.
- iamnothere 11mo agoMore people should run their own recursive resolvers with unbound. There’s no need to rely on centralized DNS anymore.
- kavouras 11mo agoIsn't this putting unsustainable load on the root servers?(on the scenario that many people do that)
- seethishat 11mo agohttps://datatracker.ietf.org/doc/html/rfc8806 https://datatracker.ietf.org/doc/html/rfc8806 Abstract Some DNS recursive resolvers have longer-than-desired round-trip times to the closest DNS root server; those resolvers may have difficulty getting responses from the root servers, such as during a network attack. Some DNS recursive resolver operators want to prevent snooping by third parties of requests sent to DNS root servers. In both cases, resolvers can greatly decrease the round-trip time and prevent observation of requests by serving a copy of the full root zone on the same server, such as on a loopback address or in the resolver software. This document shows how to start and maintain such a copy of the root zone that does not cause problems for other users of the DNS, at the cost of adding some operational fragility for the operator. This document obsoletes RFC 7706.
- belorn 11mo agoIf we are talking about the actually root servers, there are 13 redundant names spread out (thanks to anycast) on around 1700 servers located around the world, and the lookup a user would do is cached for 2 days. That mean the highest amount of traffic a system will generate is one request per unique TLD (like .com) per 2 days, and it will fit a single UDP package. We can then do some guesses about size for questions like "what is the nameservers for .com". Those are a bit larger than most dns queries since the answer is a bit bigger than most, since .com has a lot of nameservers, so lets put it down to 800 bytes. Every 2 day a average use might then, using some guessing, generate maybe 10 kb of traffic, or about 0.015 seconds of watching a 1080p video on youtube.
- ectospheno 11mo agoRFC 7706. Even has config file examples.
- Bender 11mo agoEveryone used to query the root servers directly from their ISP or corporate edge servers until the big platforms wanted to gather more of everyone's data in the name of "keeping people safe" from "bad ISP's". As with any manipulation campaign there are a few incidents corporate propagandists can site to say, "See! We are protecting you!!" forcing people to debate the issue and knowing the majority will accept the default settings. Blocking all the DoH/DoT resolvers would be trivial for any ISP to do just as I have been doing at home since the inception of DoH. The root Anycast clusters are absolutely designed to handle the entire internet querying them which I do from Unbound. If one wishes to help reduce load they can enable large memory caches and rewrite min-ttl to something sane to protect the root servers from Amazon EC2's default 5 second ttl and others like them. Blocking known spam and tracking domains also helps reduce the total number of queries. Groups of friends can even further reduce the load by setting up their own DoH/DoT servers using Unbound DNS and sharing the cache and using cron to keep their favorite domains hot in the cache and increasing private by making the crond queries from a VPS node. Here's my cache stats for a 3 day uptime: total.num.cachehits=18149 total.num.cachemiss=2300 total.num.prefetch=4561 Memory usage permitting up to 1.5 GB: Private + Shared = RAM used Program 343.1 MiB + 523.5 KiB = 343.6 MiB unbound
- giantg2 11mo agoSeems like a great use case for Pi-hole to add include lists - have files with lists of DNS entries that are delisted in some areas. Of course a VPN is probably more beneficial in general though.
- celsoazevedo 11mo agoRegarding censorship, that works only if there's no network side blocking, otherwise the unencrypted requests to root servers also get intercepted. That's why some people use DoH as the upstream for their resolver. Not all countries or ISPs do this, but some do.
- iamnothere 11mo agoTrue, DNSSEC should tell you if requests are being rewritten or blocked, but it will not help you circumvent this.
- kidmin 11mo agoIn Japan the PM's office once considered to block online piracy websites[1] with DNS in 2018. Japanese tech community fought against it[2][3][4] and it wasn't implemented. The telco authority currently considers to block online casino websites[5] (gambling is illegal in Japan). [1] https://www.kantei.go.jp/jp/singi/titeki2/tyousakai/kensho_hyoka_kikaku/2018/kaizoku/dai1/gijisidai.html https://www.kantei.go.jp/jp/singi/titeki2/tyousakai/kensho_h... [2] https://www.nic.ad.jp/ja/topics/2018/20180625-01.html https://www.nic.ad.jp/ja/topics/2018/20180625-01.html [3] https://www.wide.ad.jp/News/2018/20180912.html https://www.wide.ad.jp/News/2018/20180912.html [4] https://www.nic.ad.jp/ja/materials/iw/2018/proceedings/d3/d3-shimamura.pdf https://www.nic.ad.jp/ja/materials/iw/2018/proceedings/d3/d3... [5] https://www.soumu.go.jp/main_sosiki/kenkyu/online_casino/index.html https://www.soumu.go.jp/main_sosiki/kenkyu/online_casino/ind...