Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dc396
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
dc396
1y ago
Fair warning: you have to log in prior to seeing example output. Would've been nice to know prior to entering information.
92.
▲
by
dc396
1y ago
What a particularly stupid way of distracting from the Epstein files.
93.
▲
by
dc396
1y ago
I guess it's just too bad if you're immunocompromised, allergic to vaccines, too young to be vaccinated, in the middle of a virulent, highly transmissible pandemic, etc. -- wouldn't want to protect society from disease ravage
94.
▲
by
dc396
1y ago
To paraphrase Captain Renault, "I'm shocked, shocked, to find that cocaine use is going on in here."
95.
▲
by
dc396
1y ago
Accusing ICANN of incompetence when you can't be bothered to configure your DNS to avoid leaking queries to the root is an interesting approach.
96.
▲
by
dc396
1y ago
The parent comment said "cross country".
97.
▲
by
dc396
1y ago
You might want to look at the "domain" directive of resolv.conf and the concept of "split horizon DNS".
98.
▲
by
dc396
1y ago
Ah, resolver (not DNS) search paths. They were a really bad idea that can and do lead to leaked queries that can result in all sorts of unpleasantness and risks. As for certs, AFAIK, you can't get a certificate for a non-fqdn from a pu
99.
▲
by
dc396
1y ago
The DNS is hierarchical. How would you replace TLDs?
100.
▲
by
dc396
1y ago
Well, it depends. If all you were interested in was getting a "good" (e.g., short) name in .COM, no. In the late 90s, when NSF allowed Network Solutions to charge for domain names, people complained that they (now Verisign) had a
101.
▲
by
dc396
1y ago
I'm not sure what you mean by "DNS allows search" -- by the usual definition of "search", the DNS doesn't: it is a lookup mechanism. I'm also not sure who "we" are in your idea or what you mean b
102.
▲
by
dc396
1y ago
.VA is a country code TLD, assigned because it is listed in ISO-3166. The others are "generic top-level domains" which had to go through ICANN's new gTLD program, which has a lot of rules (338 pages of them for the 2012 roun
103.
▲
by
dc396
1y ago
Ignoring the point that climate sensitivity wasn't in the parent comment, AFAIK, airplanes generate 0.16 kg/km, whereas trains are around 0.1 kg/km and container ships are at 0.016 kg/km. However, passenger ships and gas
104.
▲
by
dc396
1y ago
That's quite a reach. Corruption in Washington DC causes people to die through environmental, engineering, and military catastrophes. It leads to a degradation of rule of law throughout the country and even the world. Corruption in stu
105.
▲
by
dc396
1y ago
Yes, US rail is pathetic, at least for passenger travel. However, a quick search on Google Flights shows a one-way ticket from LA to DC costs $98.00 on Frontier via Atlanta (YMMV) so I don't think it's correct to say there isn
106.
▲
by
dc396
1y ago
User experience is always at the whim of ISP agreements unless you are paying for point to point links. Sounds like you're experiencing vagaries of somebody (maybe Cloudflare, maybe some other ISP Cloudflare is peering with) doing traf
107.
▲
by
dc396
1y ago
> corruption at that [student gov't at large state universities] level is probably just as impactful as corruption in Washington, DC. Um, what?
108.
▲
by
dc396
1y ago
A few possible answers: inflation, cost to upgrade infrastructure to keep up with e.g., DDoS attacks, costs to deal with revised ICANN rules, etc. And/or greed. A TLD is a bit more than simply a registry of domain names. For gTLDs, you
109.
▲
by
dc396
1y ago
Just don't say bad things about the king...
110.
▲
by
dc396
1y ago
Nope. A variation on Ribbon filters ( https://engineering.fb.com/2021/07/09/core-infra/ribbon-filt... ). See https://hacks.mozilla.org/2025/08/crlite-fast-private-and-co... .
111.
▲
by
dc396
1y ago
> Too many domains which are incorrectly configured leading to non-existing domain errors. That's an interesting and somewhat surprising data point given the use of DNSSEC validation at public resolvers (e.g., 1.1.1.1, 8.8.8.8, etc.
112.
▲
by
dc396
1y ago
So you're saying the end user does not care about the data (IP addresses, mail servers, etc.) for the domain names they're trying to reach and they'd be perfectly happy (say) going to the IP address of an attacker controlled
113.
▲
by
dc396
1y ago
I'm unclear there is a security issue with dnsmasq -- maybe leaving a transaction alive too long (but then again, what does "too long" mean these days?). However, I haven't looked into the "vulnerability" refer
114.
▲
by
dc396
1y ago
While the functionality/complexity of dnsmasq makes me nervous and I use it (I don't have a use case for it), it isn't clear to me that dnsmasq is doing anything wrong in this particular case.
115.
▲
by
dc396
1y ago
I guess you and I were at different meetings. I was at meetings at NSF with TIS folks that resulted in funding for DNSSEC implementation in BIND where the presentation focused on the 16-bit transaction field (and included a live demonstrati
116.
▲
by
dc396
1y ago
Transport security protects the channel, not the data. DNSSEC protects the data so that the channel doesn't matter. Given how the DNS is deployed particularly in enterprise environments, there have been too many times when protecting t
117.
▲
by
dc396
1y ago
It's unclear to me what "make the DNS security model cohere with IPSEC" means. DNSSEC was a direct response to the vulnerabilities identified by a number of folks and documented by Christoph Schuba ( https://www.cer
118.
▲
by
dc396
1y ago
> Query ID prediction attacks are not in fact the point of DNSSEC Do you deny DNSSEC's goal is to protect DNS data? Do you deny "Query ID prediction attacks" (or more generally, flooding attacks) aim to corrupt DNS data? D
119.
▲
by
dc396
1y ago
> DNSSEC was created because we needed to put root and gTLD servers in Russia and China (lying authoritatives). Interesting assertion -- do you have anything to back this up? While DNSSEC can prevent a name server operator from effective
120.
▲
by
dc396
1y ago
Does dnsmasq have a way to forward via DOH/DOT? (I've no idea: I don't use it myself)
More ›