[HN Gopher] The prevalence, persistence, and perils of lame dele...
       ___________________________________________________________________
        
       The prevalence, persistence, and perils of lame delegations (2021)
        
       Author : fanf2
       Score  : 20 points
       Date   : 2024-06-23 08:42 UTC (14 hours ago)
        
 (HTM) web link (blog.apnic.net)
 (TXT) w3m dump (blog.apnic.net)
        
       | m3047 wrote:
       | Lame delegations are a scourge, like untreated venereal disease;
       | often accompanied by a similar refusal to acknowledge
       | externalities... or that there's any problem at all: works for
       | me! But the DNS community, or bright people trying to do other
       | things with DNS (I'm one of them), often bring it on themselves.
       | 
       | For instance let's just go down the "until they find a server
       | that isn't lame" rabbit hole: let's look at a server which isn't
       | actually authoritative for the domain it serves. Maybe they're
       | all lame, sorry.
       | 
       | It could be a recursive, and it should be obvious that AA isn't
       | present in the response. But in the real world, people with their
       | own root are forced to lie in order to publish data in the public
       | (root) namespace. This is baked into server configs as forwarding
       | zones for those too lazy to recompile BIND to always return AA.
       | Not that anybody checks, the DNS still works, so why bother? But
       | the root (ha ha, pun!) of the problem is the obsession with One
       | True Root which is staunchly defended by ICANN, kind of like the
       | petrodollar.
       | 
       | Or it could be authoritative, but not for the zone which it is
       | properly delegated. Take my ISP, please. They impersonate the
       | people who delegate their /17 in reverse DNS; I assume it's
       | because they're too lazy or incompetent to manage 128 /24s. Fun
       | fact: sometimes recursives subsisting on this diet of excrement
       | report that they ARE authoritative for the delegator's /16! The
       | delegator doesn't care, they block email reports from their own
       | /17 so no worries about anyone cleaning up after GG Allin
       | finishes his show.
       | 
       | But the DNS authoritahs bring it on themselves: "Additionally,
       | the queries to lame delegated nameservers represent additional
       | load on the network, and at the incorrectly delegated nameserver.
       | For example, incorrectly configured domains represent 12% of
       | queries to GoDaddy nameservers: one out of eight queries received
       | by a GoDaddy nameserver is a lame query, a query for which the
       | GoDaddy nameserver is not authoritative." Cry me a river. Qname
       | minimization can effectively double the number of (unprimed)
       | queries required to resolve a name. Coincidentally, qname
       | minimization issues requests which are intended to fail (hoping
       | for SOA) and NS requests which are unnecessary under the archaic
       | recursion algorithm which they vigorously defend by farting in a
       | different direction. Needless to say, qname minimization doesn't
       | work well with lame servers.
       | 
       | I could go on, but I won't.
        
       ___________________________________________________________________
       (page generated 2024-06-23 23:02 UTC)