Post APtWdX3uPr2kuPQe8m by aeden@dnsimple.social
 (DIR) More posts by aeden@dnsimple.social
 (DIR) Post #APrznZk5oWnoTLNhYW by coffee@mastodon.kakafe.ga
       2022-11-22T18:17:26Z
       
       0 likes, 0 repeats
       
       Thinking about it, we put a ton of #trust into #DNS providers
       
 (DIR) Post #APs0mdIhCQSjAjgHTs by kali@indieweb.social
       2022-11-22T18:28:28Z
       
       0 likes, 0 repeats
       
       @coffee I know right? I’ve been encrypting my connection to cloudflare for better privacy but that doesn’t feel like enough because I don’t know how it looks on the backend
       
 (DIR) Post #APs18sDOQcb9nco1AW by coffee@mastodon.kakafe.ga
       2022-11-22T18:32:30Z
       
       0 likes, 0 repeats
       
       @kali well, i meant trust on the root servers, I know there are like 10 from different companies on different countries, but still.I wonder how the registrar's work, .com has a similar setup as the root servers, but how about the smaller TLDs?
       
 (DIR) Post #APs1AHix4WXJChEwwC by coffee@mastodon.kakafe.ga
       2022-11-22T18:32:46Z
       
       0 likes, 0 repeats
       
       @kali although trust on the "local" provider is also a thing
       
 (DIR) Post #APs1kawx4IEvFy6PmC by kali@indieweb.social
       2022-11-22T18:39:19Z
       
       0 likes, 0 repeats
       
       @coffee and also to add on, DNS is unencrypted by default! I am only aware of that because my school uses deep packet inspection to filter network traffic and monitor students browsing history by forcing everyone to connect to their network DNS service. They made it a point to block common ipv4 dns servers to make it harder to get around.I know that TLDs are licensed to registrars by some domain name authority so i’d guess that they would hold a definitive for others to cache
       
 (DIR) Post #APsCedPC7nOed9fnv6 by lspgn@fosstodon.org
       2022-11-22T20:41:26Z
       
       0 likes, 0 repeats
       
       @coffee @kali do you mean trust in a technical sense? Varies from TLD to TLD, usually anycast from different subnets (eg for your .ga: https://www.iana.org/domains/root/db/ga.html). Sometimes small TLDs delegate to other larger ones. Eg: French's AFNIC handles metropolitan France and the oversea territories (.re, .pm, .tf).The .io was also not advised due to outages despite popularity for tech startups.
       
 (DIR) Post #APtWdX3uPr2kuPQe8m by aeden@dnsimple.social
       2022-11-23T12:00:05Z
       
       0 likes, 0 repeats
       
       @coffee very much true.