Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ate53
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
ate53
4y ago
It's a viable strategy. No legitimate implementation produces compression pointers that go anywhere other than backwards. I track the start of a label sequence and whether I've followed a pointer. If I've just followed a poin
2.
▲
by
ate53
5y ago
https://powerdns.org/hello-dns/
3.
▲
by
ate53
5y ago
> On the TLSA side, the argument is roughly that (1) the WebPKI is bad ... Is that a common argument? I've seen it argued that WebPKI shouldn't be used because it outsources DNS trust to the CAB forum, but not "WebPKI is b
4.
▲
by
ate53
5y ago
There's private use ranges for classes and types. They don't have specific mnemonics but you can use the generic ones (eg: CLASS65280 and TYPE65280). CHAOS probably gets used most because that's what BIND happened to do.
5.
▲
by
ate53
5y ago
A possibly needless clarification: The DNS is organised by class, name, and then type. Each class is a seperate space, so ycombinator.com in the IN (Internet) class and ycombinator.com in any other class aren't necessarily the same ent
6.
▲
by
ate53
5y ago
I can understand how you might arrive at such an intuition but I'm not sure how well it serves you, particularly when you apply it outside of the search results that have formed it. There's over 150 million names under .com, peopl
7.
▲
by
ate53
5y ago
> ... especially on a "nonstandard" TLD. I guess that's a dig but I'm not sure why. It's resolvable via the ICANN root and is no more "nonstandard" than any of its siblings.
8.
▲
by
ate53
5y ago
Has anyone here had experience with Glauca? I'm curious about them because they support RFC 2136.
9.
▲
by
ate53
5y ago
Namecheap's DNSSEC implementation has broken a number of times and last I looked their API was pretty poor.
10.
▲
by
ate53
5y ago
My problem with this spec is it requires Service Providers and DNS Providers to know about each other. It's essentially formalising the status quo of cookie cutter setups for big name providers.
11.
▲
by
ate53
5y ago
Dynamic responses make transfers difficult to implement in some server architectures. Which is not to take away from your point - trying to hide things in the DNS is a fairly pointless exercise.
12.
▲
by
ate53
5y ago
IXFR is for incremental transfers in which the client asks for a series of diffs between a particular serial and the current one. AXFR requests a transfer of the full zone. dig supports supports both.
13.
▲
by
ate53
5y ago
> Multiple questions inside the same packet are quite common in DNS-SD based multicast queries. mDNS is DNS in name only. Yes the wire format is mostly the same but the semantics are not. > Note that technically, servers have to suppo
14.
▲
by
ate53
5y ago
> deactivate message compression if possible. PowerDNS tried this early on, it ended poorly because a client with a large installed base assumed that answers following the question section would start with a compression pointer.
15.
▲
by
ate53
5y ago
What was the implementation that produced the bad NSEC3 proofs?