[HN Gopher] Italy demands Google poison DNS under strict Piracy ...
       ___________________________________________________________________
        
       Italy demands Google poison DNS under strict Piracy Shield law
        
       Author : DanAtC
       Score  : 81 points
       Date   : 2025-03-22 19:46 UTC (3 hours ago)
        
 (HTM) web link (arstechnica.com)
 (TXT) w3m dump (arstechnica.com)
        
       | Kenji wrote:
       | DOH is your friend. My regime poisons DNS and enabling DOH makes
       | things accessible again.
        
         | geoffpado wrote:
         | Serious question: how is DoH supposed to help when the resolver
         | itself is being asked to return bad results? DoH makes sense if
         | something is MITM-ing your DNS requests, but it sounds in this
         | case that Google is being asked to just straight-up return bad
         | results?
        
           | mantas wrote:
           | DOH over proxy to pretend you're elsewhere?
        
           | Nux wrote:
           | DoH some other resolver, there's an internet outside Google,
           | you know.
        
             | mlhpdx wrote:
             | Exactly. In a world of many resolvers, poisoning a few
             | doesn't matter. In all likelihood the folks consuming these
             | streams aren't using mainstream DNS anyway.
        
           | vhcr wrote:
           | DoH over Tor
        
           | xxmarkuski wrote:
           | DNSSEC is the actual solution, providing authenticity and
           | integrity for DNS records. The DNS client can verify that the
           | received DNS response is what the zone admin intended.
           | Additional records (NSEC / NSEC3) are used to provide a proof
           | of non-existence, preventing suppression from a mitm
           | attacker. But if your government is mitming you, you don't
           | want them to see you use DNSSEC. DoH is useful in that case,
           | because a mitm sees only https traffic, which is less
           | suspicious than DoT.
        
             | crote wrote:
             | DNSSEC isn't going to _prevent_ suppression, it just makes
             | it detectable. Cloudflare is still going to send you a
             | doctored record - which will fail verification. But that
             | doesn 't magically give you an undoctored record,
             | unfortunately.
        
           | thayne wrote:
           | I think the actual reason this works is because if you use
           | DoH, you are probably also setting your resolver to something
           | other than the default, which might not be poising the
           | records.
           | 
           | So the real answer to governments requiring dns resolvers to
           | censor results is to ... not use those resolvers. which is
           | actually relatively easy to do. But most internet users don't
           | even know what a dns resolver is, much less how to configure
           | their browser to use a public resolver that isn't big enough
           | to attract the attention of your government.
        
           | miki123211 wrote:
           | It would not.
           | 
           | You'd need a resolver that was provided by a foreign
           | organization, preferably a non-profit, with no business
           | interests in your country whatsoever, so that your government
           | had nothing to threaten them with if they didn't comply with
           | the order.
           | 
           | Such a resolver would also need to be the default shipped
           | with at least one major browser, such that blocking it would
           | essentially mean "turning off the internet" for some users.
           | 
           | Then the pressure would move to forcing browsers to use a
           | different DNS resolver, and the game would continue.
        
       | djoldman wrote:
       | > This decision follows a similar case against Internet backbone
       | firm Cloudflare. In January, the Court of Milan found that
       | Cloudflare's CDN, DNS server, and WARP VPN were facilitating
       | piracy. The court threatened Cloudflare with fines of up to
       | 10,000 euros per day if it did not begin blocking the sites.
       | 
       | I'm always curious about jurisdiction on this stuff.
       | 
       | If Cloudflare had no physical machines, employees, and property
       | within Italy's borders, under what law could Italy levy a fine?
        
         | miohtama wrote:
         | The EU companies make payments to Cloudflare, and these could
         | be confiscated. Also any staff in Italy is in danger.
        
           | AdrianB1 wrote:
           | The question clearly stated the assumption that there is no
           | staff in Italy. Also the payments cannot be confiscated
           | unless they are made to Italian banks, which makes no sense
           | if they don't have a branch there, so if the payments are
           | made to US, there is no way to confiscate by the Italian
           | authorities.
        
             | nukem222 wrote:
             | Presumably italian courts could seize payments made by
             | italian clients of cloudflare, yes? Even if the account is
             | located well outside of italy, the owners can be compelled
             | by legal means.
             | 
             | (To some degree of effectiveness, to be sure. But I have a
             | hard time imagining there are no clients registered in
             | italy at all.)
        
               | AdrianB1 wrote:
               | The payment is done, money is at Cloudflare in a US bank,
               | Cloudflare takes it and move it somewhere else. How do
               | they seize it? The money is gone and it's not coming
               | back.
        
               | nukem222 wrote:
               | Assuming the client is an italian company, as would make
               | sense in this thread, they would issue a court order
               | compelling the corporation to comply with domestic law or
               | get fined (or worse, idk, this is all speculative).
               | Presumably the ask would be handing over control of the
               | client's bank account for the needs of the court
               | fulfilling its duties moving forward from the court
               | order.
               | 
               | Edit: corrected mistake about whose account would be
               | within the court's grasp.
        
               | rvnx wrote:
               | It's more simple, imagine Cloudflare is used to show
               | pedophile content, and refuses to remove it. Then the
               | solution is to cut access to Cloudflare.
               | 
               | That's the logic here. It's not about whether they have
               | offices or not, but whether they are distributing content
               | to users in Italy.
               | 
               | There is always a local relay or ISP in Italy that offers
               | access to Cloudflare, and this relay can be coerced into
               | blocking Cloudflare.
               | 
               | Of course 1% of people may be able to access otherwise
               | (for example, via Starlink or VPNs), but the objective is
               | to block 90%+ of the traffic, so Cloudflare reconsiders
               | following local laws.
        
               | nashashmi wrote:
               | Connections to foreign computers are not subjected to
               | regulation currently.
        
         | bakugo wrote:
         | Unfortunately, even if we ignore the fact that Cloudflare
         | probably has many Italian customers, there are other ways they
         | can interfere with Cloudflare's services, such as by blocking
         | their IP addresses in the country. It wouldn't be the first
         | time this has been done by European ISPs, sadly.
        
           | AdrianB1 wrote:
           | Is that a problem for Cloudflare or with Italy? In the end,
           | can Italy break Internet or can Internet cut off Italy? It is
           | a theoretical question, I wonder how much control countries
           | can have over a non-country level concept as Internet. The
           | jurisdiction question is very much the point, does Cloudflare
           | or Google provide a paid DNS service to Italian clients and
           | the contract is regulated by Italian laws or it is a
           | universal and free DNS service that Italy cannot regulate?
        
         | theow939494 wrote:
         | Many many years ago there was a case, when youtube showed
         | school bullying video from Italy, in recommended content, for
         | several weeks.
         | 
         | If I remember correctly, Italy criminally charged some YT
         | execs, and asked Interpol to get them.
        
         | Etheryte wrote:
         | I'm not sure how there's any ambiguity to this? We're talking
         | about the EU here. The same laws that enable you to do business
         | across borders without having a legal presence in every country
         | also outline how to deal with issues like these.
        
         | Aachen wrote:
         | What do you mean what law? See the court case, they've issued
         | it and so they can either pay it or see what Italy wants to do
         | about it
         | 
         | If you get a speeding ticket in North Korea and fly off before
         | it arrives at the car rental, you can ask what law the rental
         | is going to use to get the money from you abroad. You can not
         | pay and choose to never visit the country again. In
         | Cloudflare's case, however, they probably want to continue
         | doing business in that market so just fleeing with the money is
         | not likely the most profitable option for them
         | 
         | There's tons of international cases if you want to know more.
         | It's also a common (to the point of trite) discussion point
         | about GDPR saying it applies globally. Obviously it doesn't
         | unless the non-treaty country lets an EU/EEA country enforce it
         | (I am not aware that this ever happened) if the fined party
         | does not care to continue doing business in the EEA
        
         | miki123211 wrote:
         | The point of Cloudflare is that it's widely available and that
         | _your_ customers can connect to it. Italy could block
         | Cloudflare access to Cloudflare for its citizens, which would
         | make non-italian CF customers who have users in Italy extremely
         | unhappy.
         | 
         | Imagine an American SaaS company that uses Cloudflare CDN to
         | distribute their assets and tunnels their traffic through CF
         | for DoS mitigation. That company has paying customers in Italy.
         | If Cloudflare gets blocked, that company's software no longer
         | works in that country. They have a choice between switching to
         | a different provider (which will make Cloudflare lose money)
         | and telling their Italian customers to go away (which they
         | don't want to do for obvious reasons).
         | 
         | Considering how much infra actually relies on CF, Whether the
         | Italian government would actually fight that fight is a
         | different matter entirely. Sometimes centralization is a good
         | thing.
         | 
         | IMO, a far more interesting question is what would happen if
         | Italy asked CF to block some content _worldwide_.
        
           | ajsnigrutin wrote:
           | CF blocking a whole country like this would be interesting...
           | basically half the internet would stop working, probably a
           | bunch of italian government stuff too, and people would
           | hopefully blame the government, because i'm pretty sure there
           | are almost zero italian voters who wanted this from their
           | representatives.
           | 
           | Sadly, companies bow down instead of just risk it once.
        
         | jimnotgym wrote:
         | That is a big 'if' though. Don't CDNs work by having equipment
         | in every country so you don't have to?
        
       | bakugo wrote:
       | > The goal is aimed at preventing illegal football streams
       | 
       | It's impressive how much internet censorship in Europe is
       | currently being caused by this one group of extremely greedy
       | people. It's one of the rare cases where the sheer size and
       | international influence of companies like Google and Cloudflare
       | can actually do some good for the world by fighting back against
       | such laws.
        
         | delroth wrote:
         | > It's impressive how much internet censorship in Europe is
         | currently being caused by this one group of extremely greedy
         | people.
         | 
         | How is this greedy? It's clearly illegal behavior, both from
         | illegal re-broadcasters and from users. Most of those re-
         | broadcast services aren't even free either, they're directly
         | making money from the broadcasts they're replicating.
         | 
         | The problem is that we still haven't figured out a way to
         | properly enforce laws on the internet. Even for completely
         | egregious violations there's no way to do anything once you
         | track down the website to a bulletproof host in Russia or
         | Ukraine or similar countries that don't cooperate. After 20
         | years of getting nowhere the courts have to find new and
         | creative ways to enforce laws. I think everyone agrees that
         | ideally this shouldn't be DNS blocks or IP blocks but rather
         | these services getting removed from the internet and/or having
         | to implement regional blocks to comply with laws. But there's
         | just no way at all to make this happen right now.
        
           | TeMPOraL wrote:
           | > _How is this greedy? It 's clearly illegal behavior, both
           | from illegal re-broadcasters and from users. Most of those
           | re-broadcast services aren't even free either, they're
           | directly making money from the broadcasts they're
           | replicating._
           | 
           | It's _both_. The re-broadcasters may be violating the laws
           | _and_ laws themselves could be unjust, nonsensical, yet
           | existing and enforced because of a group of greedy
           | benefactors actively keeping them that way.
        
           | bakugo wrote:
           | > How is this greedy? It's clearly illegal behavior, both
           | from illegal re-broadcasters and from users. Most of those
           | re-broadcast services aren't even free either, they're
           | directly making money from the broadcasts they're
           | replicating.
           | 
           | Because piracy is a service problem. Pirate streaming sites
           | attract users because they provide a better, more convenient
           | service than the paid options.
           | 
           | We've recently seen this happen in real time with TV/movie
           | streaming services: If you simply tell users "Pay us this
           | single, simple and affordable fee every month and we will
           | provide you with unrestricted access to the content you want,
           | whenever you want", the users will come. But then the
           | investors come knocking. It's not enough that you made N
           | money last quarter, you have to make N+1 next quater. The
           | line has to go up. So the subscription prices go up, the
           | number of subscriptions required to access everything goes
           | up, you start getting ads even though your subscription was
           | originally ad-free, and suddenly the service doesn't seem so
           | appealing anymore.
           | 
           | I've heard endless stories of people having to pay for
           | multiple subscriptions just to watch all of their favorite
           | team's games, and still missing out on some due to whatever
           | new money-making scheme sports companies came up with this
           | month. It's not hard to see why so many people resort to just
           | going online and finding a pirate stream.
        
           | AdrianB1 wrote:
           | So basically the problem is reduced to "how can Italy fight
           | against a crime happening somewhere in Russia or Ukraine"?
           | Imagine there is a TV broadcast from Russia, how can Italy
           | forbid it? They can definitely disrupt it (by electronic
           | jamming), but not forbit it. Similar to Internet, the
           | difference is the medium of transmission, not the facts of
           | the matter.
           | 
           | In Communist times in my country I was watching cartoons
           | broadcasted from the neighboring country. Adults were
           | watching adult content at night from the same source. There
           | was no way to stop that.
        
         | timewizard wrote:
         | > is currently being caused by this one group of extremely
         | greedy people.
         | 
         | You can be sure it's not limited to just them. This just
         | appears to be the most publicized example because the
         | government happens to be the unusual position that the entity
         | under scrutiny has far more money and legal power than they do.
        
         | lifestyleguru wrote:
         | Mediterranean EU is all about lotteries, gambling, and
         | football. Don't allow them to change anything related to how
         | the internet works. It will be awful internet.
        
       | perching_aix wrote:
       | Am I correct in recognizing this as a _new_ low, or is there a
       | prior example for such a demand?
        
         | miohtama wrote:
         | A Spanish judge ordered blocking of Telegram for the same
         | reason.
         | 
         | https://medium.com/enrique-dans/why-blocking-telegram-in-spa...
         | 
         | It was reversed quickly on complaints, though.
        
         | int_19h wrote:
         | Right there in the article:
         | 
         | "This decision follows a similar case against Internet backbone
         | firm Cloudflare. In January, the Court of Milan found that
         | Cloudflare's CDN, DNS server, and WARP VPN were facilitating
         | piracy. The court threatened Cloudflare with fines of up to
         | 10,000 euros per day if it did not begin blocking the sites."
        
           | perching_aix wrote:
           | I was specifically referring to requesting DNS poisoning.
        
         | threeseed wrote:
         | ISPs being asked by the government to block sites at the DNS
         | level is very common.
        
       | stalfosknight wrote:
       | Why must the Europeans be like this? Why do they insist on
       | fucking with a free and open internet instead of addressing the
       | apparently unmet demand that is fueling a black market?
        
         | amarcheschi wrote:
         | Please, do not confuse Europeans with the entities taking such
         | actions. I know of nobody supporting such draconian measures.
         | However, the government, the football league and the guys
         | taking decisions at agcom (which in the past has been a serious
         | and respected agency for the battle he took with tech
         | companies) are, quite apparently, banding together to make the
         | football league will become reality above anything else
        
           | stalfosknight wrote:
           | While I generally agree that one should not conflate private
           | individuals with the actions of their government, I do think
           | it is fair to hold people who live in democracies responsible
           | in a general or aggregate sense for the actions of their
           | elected governments.
           | 
           | In other words, I think it is fair to say that Italy pulls
           | shit like this because enough Italian voters want it to
           | happen or otherwise let it happen.
        
             | amarcheschi wrote:
             | Heh, I partially agree with general politics, however
             | actions like this are so distant from the average Joe that
             | the chances are they do not even know the pros and cons of
             | similar actions. One might argue that they can get
             | informed, but once you get into technicalities like this,
             | one should spend its entire free time getting informed on
             | similar issues. I see a lack of general discourse about
             | this - in the past it happened to have some Google drive
             | urls blocked if I'm not wrong - because it is not perceived
             | as an issue unless something big happens that (such as
             | drive not working)
             | 
             | You also have to add the fact that this issue goes
             | relatively "unnoticed" compared to other issues that are
             | perceived as much more important
        
             | scns wrote:
             | > I do think it is fair to hold people who live in
             | democracies responsible in a general or aggregate sense for
             | the actions of their elected governments.
             | 
             | Are you american? Should you be held responsible for
             | Trumps' and Musks' actions?
        
           | drpossum wrote:
           | Yeah! Didn't you know? Europe doesn't have elected leaders.
        
             | amarcheschi wrote:
             | I am not sure if I'm understanding what you're saying.
             | Anyway.
             | 
             | What I am against is equating leader's behavior and
             | people's behavior. It's not a nazi Germany situation where
             | the people supported this action, it's a situation where
             | most people don't know about it, and those who know are
             | probably against it. It's such a minor issue that until
             | something very big will happen and go on the news, nobody
             | will care about it since people are mostly trying to make a
             | living without much thought about what happens outside
             | their garden
        
           | xvector wrote:
           | Europeans consistently support a regulation regime that
           | routinely pushes absurd tech policy. It sounds great to
           | normies so it goes unresisted. But it's a complete fucking
           | nightmare for anyone trying to actually build+ship anything.
        
         | miki123211 wrote:
         | For one simple reason.
         | 
         | If the US wants some content gone from the internet, they
         | (usually) have enough might to make that happen.
         | 
         | Most major tech companies are registered in the US, and can be
         | ordered by a US court to stop providing services to pirates.
         | This notably includes most major DNS registrars, reputable ad
         | networks and major payment processors.
         | 
         | There's no point in blocking a website if you can just boot it
         | off Visa, or force it to show penis enlargement / shady
         | gambling ads or malware popups to survive.
         | 
         | Even if a website miraculously has no US links to exploit,
         | there are extradition treaties, good relations with foreign law
         | enforcement, control over the financial system, or even
         | international sanctions if the situation gets dire enough.
         | 
         | European countries are far less powerful here, especially when
         | they act alone (as they usually do in these matters) instead of
         | doing it under the auspices of the EU. Site blocking is often
         | the only remedy they have.
         | 
         | The US has an opposite problem with scam calls. Because there
         | are so many English speakers in India, and Indian law
         | enforcement largely doesn't care about scammers as long as they
         | scam foreigners, there's little the US can do about the issue.
         | European countries whose first language is not English have it
         | much easier, as there's often no third-world country that
         | speaks the same language and where the scammers could be
         | recruited from.
        
           | yimby2001 wrote:
           | What piracy has the US government ever stopped? The pirate
           | bay is up all the free movie tv.com sites are up
        
       | ur-whale wrote:
       | If there is ONE thing that needs to be decentralized RTFN, it is
       | DNS.
       | 
       | It's taking time, but the thugs in charge in various countries
       | are slowly coming to realize that the easiest place to apply
       | censorship is DNS because of its antiquated design and
       | pervasiveness.
       | 
       | One: you should be able to freely choose or name-to-IP-
       | translation provider.
       | 
       | Two: modern DNS should run on top of a trustless blockchain
       | infrastructure.
       | 
       | Namecoin was a very nice initial attempt, it's really sad it
       | never took off.
       | 
       | [EDIT]: https://en.wikipedia.org/wiki/Namecoin
        
       | xvector wrote:
       | Why is Europe like this? I feel like this is what happens when
       | you have a region that can't innovate and only knows how to
       | regulate.
       | 
       | Innovators cease to be represented at the government level and
       | the general public equates regulation with safety. The result is
       | an increasing amount of absurd policymaking related to
       | technology.
        
         | Ylpertnodi wrote:
         | >Why is Europe like this?
         | 
         | Italy isn't Europe. Europe isn't Italy, either.
        
       ___________________________________________________________________
       (page generated 2025-03-22 23:01 UTC)