[HN Gopher] DNS4EU
       ___________________________________________________________________
        
       DNS4EU
        
       Author : xrayarx
       Score  : 35 points
       Date   : 2023-01-12 07:33 UTC (1 days ago)
        
 (HTM) web link (labs.apnic.net)
 (TXT) w3m dump (labs.apnic.net)
        
       | mschuster91 wrote:
       | What I don't get anyway is why provider DNS servers are needed
       | _at all_. Customer routers can be set up as full-fledged DNS
       | resolvers, there are numerous lightweight and open-source
       | solutions for this.
       | 
       | edit: removed the reference to dnsmasq - it is one of the very
       | few DNS packages that _cannot_ do recursion [1].
       | 
       | [1]
       | https://en.wikipedia.org/wiki/Comparison_of_DNS_server_softw...
        
         | DanAtC wrote:
         | dnsmasq is not a recursive resolver.
        
           | mschuster91 wrote:
           | You are completely right, had a brain fart somewhere when I
           | wrote this. Thanks, corrected it.
        
         | 2000UltraDeluxe wrote:
         | Performance is lower when there isn't enough requests to keep
         | the more common lookups cached. A more busy resolver with the
         | more common entries cached will have a significant performance
         | advantage.
        
         | colmmacc wrote:
         | You're right, but caching would be much less effective and this
         | would place a larger load on authoritative servers, especially
         | the roots and TLDs. In-practice it would be less reliable too;
         | there are a lot of DDOS-mitigation techniques involved in
         | internet-scale DNS operations, and direct consumer resolvers
         | would fall victim to throttling and other measures at much
         | higher rates than the pseudo-centralized ISP resolvers.
         | 
         | It'd be a pretty big shift in patterns and so far the Internet
         | operator consensus has been to avoid this.
        
           | mschuster91 wrote:
           | > It'd be a pretty big shift in patterns and so far the
           | Internet operator consensus has been to avoid this.
           | 
           | Agreed, but if there is any hope to avoid even more
           | centralization to enforce censorship, that stance _has_ to
           | change. And better it changes now and gradually so that
           | everyone can adjust, than that it changes rapidly e.g. as the
           | result of opposition to yet another censorship bill.
        
             | zamadatix wrote:
             | There is very unlikely any hope there will be less
             | centralization. Not relying on a "evil theory" explanation
             | or anything it's just impractical to deploy it that way all
             | the time. The nice thing about the design is for those that
             | really do see it as critically important it allows for them
             | to do it. Since that number is low it doesn't create
             | scaling problems.
        
         | orra wrote:
         | The traditional reason was probably distributed caching, to
         | reduce the load on authorative servers.
         | 
         | Having an ISP or open resolver near you with cached results
         | alsoo means less latency, when you first look up a domain.
        
       | colmmacc wrote:
       | FWIW I suspect that by running 8.8.8.8, Google get a lot more
       | positive value out of direct visibility of the relative
       | popularity of domains, and common typos, than anything else.
       | 
       | Some ISP DNS services do use NXDOMAINs for search ("Did you mean
       | ...") ... but DNS can't cope with multiple words and it's not
       | very useful for general search.
       | 
       | Meanwhile, anonymized query data can be used to rank domains, by
       | location, time of day, and all sorts of things. All of which
       | seems like very useful data when you run a search engine and ads
       | business.
        
         | ilyt wrote:
         | > Some ISP DNS services do use NXDOMAINs for search ("Did you
         | mean ...")
         | 
         | Which is one of big reasons why people switch away from them.
         | Fucking with DNS
        
       | nforgerit wrote:
       | As a German currently residing in his severely dysfunctional
       | state, I much appreciate the EU. But a DNS controlled by
       | government really sounds like a bad idea.
       | 
       | Together with their recurring war on child pornography as an
       | excuse for more advanced spying on their citizens, this could
       | turn into a nightmare, when used widely.
       | 
       | AFAIK they're right now drafting a law which essentially leads to
       | providers of any kind of messengers being required to scan
       | messages on the clients for abusive material.
        
         | willyt wrote:
         | My daughter's high school, like plenty of schools in the UK, US
         | and EU, is full of 13 year old boys who think Andrew Tate
         | (YouTube advocate of wife beating currently on trial for rape
         | and sex trafficking) is innocent and a cool dude to boot.
         | Parents mostly have no idea who he is and no time to really
         | find out what their kids are looking at on the internet and not
         | enough technical knowledge to restrict it. TBH if the law said
         | that the default ISP config pointed you to a DNS that blocked
         | the shite that is piped into the heads of children who are too
         | young and stupid to step back and reason about or question what
         | they are shown, I would be happy with that as long as the law
         | says you have inviolable right to change the config to allow
         | the mind filth in if you want it.
        
           | nforgerit wrote:
           | The example you're giving is not prohibited by generally
           | applied client-side scanning, since it happens in the realm
           | of public Social Media. It's improbable politicians will
           | block YT, Insta, Fb, Twitter since they're using it
           | themselves to reach out.
           | 
           | That said, your example can be properly tackled by installing
           | more social workers in different contexts, schools in this
           | case. But neo-liberalism made politicians save money esp. in
           | social contexts. Now that dogmatic approach is falling on our
           | feet, frankly to no surprise.
        
             | lazide wrote:
             | Social workers won't do Jack here - only parenting
             | involvement.
             | 
             | Which is even less popular.
        
           | ronsor wrote:
           | Tate is YouTube's problem, not the ISP or DNS's problem. Most
           | of the stuff you're talking about mostly exists on social
           | media sites, so unless you're proposing DNS-blocking
           | Facebook, Twitter, YouTube, Instagram, TikTok, and all the
           | others by default, there's little benefit to defaulting to
           | DNS censorship.
        
       | draugadrotten wrote:
       | Of course we will all use dns4eu like good lemmings. Then the EU
       | bureacrats only need to implement the EU index DNS prohibitorum
       | in one central location. Win-Win! Or something.
        
         | [deleted]
        
       | [deleted]
        
       | thriftwy wrote:
       | That's how Russian state firewall came into being around 2013 by
       | mandating filtering of unwanted domain names.
        
         | betaby wrote:
         | 'It is different!'
        
       | jwildeboer wrote:
       | So instead of having a few European companies offering DNS
       | resolvers for the EU under documented rules, this article argues
       | its better to leave this to a few US companies that have
       | effectively zero rules to follow?
        
         | orra wrote:
         | I don't think end users win, in either scenario. The article
         | says
         | 
         | > The intended benefit is to provide a DNS resolution service
         | that is able to comply with the various content regulations in
         | the EU by blocking the resolution of certain DNS names.
         | 
         | I like GDPR enforcement, but I presume this just means
         | copyright police. Yay!
        
       ___________________________________________________________________
       (page generated 2023-01-13 23:02 UTC)