Posts by MattPounsett@fosstodon.org
 (DIR) Post #AUpUCXhkobMikZpGj2 by MattPounsett@fosstodon.org
       2023-04-18T18:36:07Z
       
       0 likes, 1 repeats
       
       The root #dns zone will be getting a new #ZONEMD record in the coming months.  The record type contains a hash that can be used to validate the entire zone (a bit like #DNSSEC does, but covering the zone as a whole, rather than select RR sets).  This is going to be very useful for anyone serving their local root zone, or who does zone data collection for longitudinal studies.https://blog.verisign.com/security/root-zone-zonemd/
       
 (DIR) Post #AYCOH2c2ViqvbkOkdM by MattPounsett@fosstodon.org
       2023-07-29T21:22:40Z
       
       0 likes, 0 repeats
       
       @bortzmeyer @b0rk This has always been my observation. It’s also one of the reasons that DNS is often given to the junior or the intern without any guidance or training… because it’s perceived as hard to screw up.
       
 (DIR) Post #AjQKwB6JtTQ4jr49Hk by MattPounsett@fosstodon.org
       2024-06-28T21:17:30Z
       
       1 likes, 2 repeats
       
       This is an absolutely metal business decision made by OpenDNS (Cisco).Court orders in France and Portugal are requiring the big open DNS resolvers (Google, OpenDNS, CloudFlare, etc.) to block resolution of a small list of domains for anyone in those countries. OpenDNS seems to have decided to not implement the blocklist, and instead will just not answer any DNS queries from inside those countries.  Change implemented on a Friday evening, for maximum surprise.#DNS #DNSBlocking #MyHero
       
 (DIR) Post #AjSLI66vW53Lwsinqa by MattPounsett@fosstodon.org
       2024-06-29T12:12:09Z
       
       1 likes, 0 repeats
       
       @Phosphenes There are some links in the marginally more detailed blog post I wrote about this.  In short, no it's not war related... the court order is over piracy of sports broadcasts.https://www.conundrum.com/blog/2024/Jun/opendns-not-available/
       
 (DIR) Post #AjSLJfgOkI3wYz406S by MattPounsett@fosstodon.org
       2024-06-29T12:31:51Z
       
       1 likes, 0 repeats
       
       @Daniel_Blake @kirill Thanks for sharing that with everyone.  The torrentfreak link, as well as a link to OpenDNS's announcement, and an example DNS response are in this other thing I wrote yesterday.https://www.conundrum.com/blog/2024/Jun/opendns-not-available/
       
 (DIR) Post #AjSLKXC7n3vsWjJaPg by MattPounsett@fosstodon.org
       2024-06-29T11:52:48Z
       
       0 likes, 0 repeats
       
       @jannem As far as I'm aware, the US hasn't tried to legislate large scale DNS blocking at the recursive server since SOPA and PIPA failed, over a decade ago.  I'm not aware of any court orders in the US requiring recursive servers to block certain domains. Can you point me to some?
       
 (DIR) Post #AjSLKYhMCQVfBsw2jY by MattPounsett@fosstodon.org
       2024-06-29T12:50:57Z
       
       1 likes, 0 repeats
       
       @jannem Those are takedowns of the domain by taking control of the domain itself.  It's changed at the authoritative, rather than involving an uninterested third party.