[HN Gopher] DNS4EU
___________________________________________________________________
DNS4EU
Author : xrayarx
Score : 35 points
Date : 2023-01-12 07:33 UTC (1 days ago)
(HTM) web link (labs.apnic.net)
(TXT) w3m dump (labs.apnic.net)
| mschuster91 wrote:
| What I don't get anyway is why provider DNS servers are needed
| _at all_. Customer routers can be set up as full-fledged DNS
| resolvers, there are numerous lightweight and open-source
| solutions for this.
|
| edit: removed the reference to dnsmasq - it is one of the very
| few DNS packages that _cannot_ do recursion [1].
|
| [1]
| https://en.wikipedia.org/wiki/Comparison_of_DNS_server_softw...
| DanAtC wrote:
| dnsmasq is not a recursive resolver.
| mschuster91 wrote:
| You are completely right, had a brain fart somewhere when I
| wrote this. Thanks, corrected it.
| 2000UltraDeluxe wrote:
| Performance is lower when there isn't enough requests to keep
| the more common lookups cached. A more busy resolver with the
| more common entries cached will have a significant performance
| advantage.
| colmmacc wrote:
| You're right, but caching would be much less effective and this
| would place a larger load on authoritative servers, especially
| the roots and TLDs. In-practice it would be less reliable too;
| there are a lot of DDOS-mitigation techniques involved in
| internet-scale DNS operations, and direct consumer resolvers
| would fall victim to throttling and other measures at much
| higher rates than the pseudo-centralized ISP resolvers.
|
| It'd be a pretty big shift in patterns and so far the Internet
| operator consensus has been to avoid this.
| mschuster91 wrote:
| > It'd be a pretty big shift in patterns and so far the
| Internet operator consensus has been to avoid this.
|
| Agreed, but if there is any hope to avoid even more
| centralization to enforce censorship, that stance _has_ to
| change. And better it changes now and gradually so that
| everyone can adjust, than that it changes rapidly e.g. as the
| result of opposition to yet another censorship bill.
| zamadatix wrote:
| There is very unlikely any hope there will be less
| centralization. Not relying on a "evil theory" explanation
| or anything it's just impractical to deploy it that way all
| the time. The nice thing about the design is for those that
| really do see it as critically important it allows for them
| to do it. Since that number is low it doesn't create
| scaling problems.
| orra wrote:
| The traditional reason was probably distributed caching, to
| reduce the load on authorative servers.
|
| Having an ISP or open resolver near you with cached results
| alsoo means less latency, when you first look up a domain.
| colmmacc wrote:
| FWIW I suspect that by running 8.8.8.8, Google get a lot more
| positive value out of direct visibility of the relative
| popularity of domains, and common typos, than anything else.
|
| Some ISP DNS services do use NXDOMAINs for search ("Did you mean
| ...") ... but DNS can't cope with multiple words and it's not
| very useful for general search.
|
| Meanwhile, anonymized query data can be used to rank domains, by
| location, time of day, and all sorts of things. All of which
| seems like very useful data when you run a search engine and ads
| business.
| ilyt wrote:
| > Some ISP DNS services do use NXDOMAINs for search ("Did you
| mean ...")
|
| Which is one of big reasons why people switch away from them.
| Fucking with DNS
| nforgerit wrote:
| As a German currently residing in his severely dysfunctional
| state, I much appreciate the EU. But a DNS controlled by
| government really sounds like a bad idea.
|
| Together with their recurring war on child pornography as an
| excuse for more advanced spying on their citizens, this could
| turn into a nightmare, when used widely.
|
| AFAIK they're right now drafting a law which essentially leads to
| providers of any kind of messengers being required to scan
| messages on the clients for abusive material.
| willyt wrote:
| My daughter's high school, like plenty of schools in the UK, US
| and EU, is full of 13 year old boys who think Andrew Tate
| (YouTube advocate of wife beating currently on trial for rape
| and sex trafficking) is innocent and a cool dude to boot.
| Parents mostly have no idea who he is and no time to really
| find out what their kids are looking at on the internet and not
| enough technical knowledge to restrict it. TBH if the law said
| that the default ISP config pointed you to a DNS that blocked
| the shite that is piped into the heads of children who are too
| young and stupid to step back and reason about or question what
| they are shown, I would be happy with that as long as the law
| says you have inviolable right to change the config to allow
| the mind filth in if you want it.
| nforgerit wrote:
| The example you're giving is not prohibited by generally
| applied client-side scanning, since it happens in the realm
| of public Social Media. It's improbable politicians will
| block YT, Insta, Fb, Twitter since they're using it
| themselves to reach out.
|
| That said, your example can be properly tackled by installing
| more social workers in different contexts, schools in this
| case. But neo-liberalism made politicians save money esp. in
| social contexts. Now that dogmatic approach is falling on our
| feet, frankly to no surprise.
| lazide wrote:
| Social workers won't do Jack here - only parenting
| involvement.
|
| Which is even less popular.
| ronsor wrote:
| Tate is YouTube's problem, not the ISP or DNS's problem. Most
| of the stuff you're talking about mostly exists on social
| media sites, so unless you're proposing DNS-blocking
| Facebook, Twitter, YouTube, Instagram, TikTok, and all the
| others by default, there's little benefit to defaulting to
| DNS censorship.
| draugadrotten wrote:
| Of course we will all use dns4eu like good lemmings. Then the EU
| bureacrats only need to implement the EU index DNS prohibitorum
| in one central location. Win-Win! Or something.
| [deleted]
| [deleted]
| thriftwy wrote:
| That's how Russian state firewall came into being around 2013 by
| mandating filtering of unwanted domain names.
| betaby wrote:
| 'It is different!'
| jwildeboer wrote:
| So instead of having a few European companies offering DNS
| resolvers for the EU under documented rules, this article argues
| its better to leave this to a few US companies that have
| effectively zero rules to follow?
| orra wrote:
| I don't think end users win, in either scenario. The article
| says
|
| > The intended benefit is to provide a DNS resolution service
| that is able to comply with the various content regulations in
| the EU by blocking the resolution of certain DNS names.
|
| I like GDPR enforcement, but I presume this just means
| copyright police. Yay!
___________________________________________________________________
(page generated 2023-01-13 23:02 UTC)