Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Charter Implements Sitefinder-esque Annoyance » Net neutrality prevents this
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« Charter Implements Sitefinder-esque Annoyance  
AuthorAll Replies

openbox9

join:2004-01-26
Alexandria, VA
·AT&T Southeast

reply to nixen
Re: Net neutrality prevents this

If you're talking about external vs internal DNS servers with a trust (inside and outside of Charter's boundary) then yes, I'll give you that. Is that how Charter's network is setup...or any ISP for that matter. My point still stands. My ISP's DNS servers are not any more secure or accurate than the Verizon DNS servers that I use as a "third-party". If you choose to use "phishmynetwork.com"'s DNS servers instead of your ISP's, then I guess you get what's coming to you. If you use a trusted set of DNS server, then life if good. After all, DNS is hierarchical and you've got to trust external servers sometime


nixen
Rockin' the Boxen
Premium
join:2002-10-04
Alexandria, VA
·Cox HSI
·Speakeasy

said by openbox9 See Profile :

If you're talking about external vs internal DNS servers with a trust (inside and outside of Charter's boundary) then yes, I'll give you that. Is that how Charter's network is setup...or any ISP for that matter. My point still stands. My ISP's DNS servers are not any more secure or accurate than the Verizon DNS servers that I use as a "third-party". If you choose to use "phishmynetwork.com"'s DNS servers instead of your ISP's, then I guess you get what's coming to you. If you use a trusted set of DNS server, then life if good. After all, DNS is hierarchical and you've got to trust external servers sometime
However, that trust architecture is a lot more knowable when you use private/internal name servers. Instead of possibly every query reply being bogus, you only need to worry "are the replies from the authoritative servers for domain X valid" (due to those authoritative servers having either been compromised or had their registration hijacked). The only way that a private/internal nameserver is potentially as vulnerable as a public/third-party nameserver as far as trust relationships is when it comes to root nameservers and/or registry information. Given the redundancy/resiliency built into and the visibility of those systems, the likelihood of a hack lasting any amount of time is very small.

-tom
--
"Experience should teach us to be most on our guard to protect liberty when the government's purposes are beneficial. The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well meaning but without understanding." -Louis D Brandeis

openbox9

join:2004-01-26
Alexandria, VA
·AT&T Southeast

Ok, I guess we'll agree to disagree. The threat difference between "internal ISP DNS servers" and "external 'trusted' DNS servers" is minimal at best. We could always throw out DNS and use the IP addresses if the world's DNS system is so potentially insecure and unreliable.


nixen
Rockin' the Boxen
Premium
join:2002-10-04
Alexandria, VA
·Cox HSI
·Speakeasy

said by openbox9 See Profile :

Ok, I guess we'll agree to disagree. The threat difference between "internal ISP DNS servers" and "external 'trusted' DNS servers" is minimal at best.
Then you're REALLY underestimating the threat differential.

If the nameserver I consult - public or private - is compromised, then potentially every query can produce a bad result

If, however, a nameserver that is authoritative for a given domain is compromised - the delegated trust you speak of - then only queries for that domain can produce bad results.

Where the difference comes in with public vs. private nameservers is the relative likelihood of compromise. Each is open to compromise to anyone that the nameserver is available to. A public/third-party nameserver is available to the Internet at large for attack. A private nameserver is available to a lot smaller set of sources for attack.

said by openbox9 See Profile :

We could always throw out DNS and use the IP addresses if the world's DNS system is so potentially insecure and unreliable.
Yeah, that's a reasonable response to your misunderstanding of my post.

-tom
--
"Experience should teach us to be most on our guard to protect liberty when the government's purposes are beneficial. The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well meaning but without understanding." -Louis D Brandeis
Forums » Charter Implements Sitefinder-esque Annoyance« Charter Implements Sitefinder-esque Annoyance  


Wednesday, 02-Dec 04:40:15 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [151] Comcast Releasing Promised Usage Meter
· [69] Baltimore To Ban Lazy Cable Installs
· [56] Broadband Killed The Game Console
· [55] Latest Consumer Reports Survey Not Kind To AT&T
· [52] Rogers Unveils The ISP Dream Model
· [41] Rural Carriers Quickly Embracing Fiber
· [37] ACTA: Global Three Strikes
· [35] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [26] Vivendi Agrees, Comcast/NBC Deal Soon
Most people now reading
· [Newsgroups] Newzleech down? [Filesharing Software]
· Security Software Updates - 1 Dec 2009 [Security]
· [Newsgroups] Newzleech is either down or gone for good... [Filesharing Software]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· MagicJack Error Broken Storage [MagicJack]
· Maximizing Rogue DPS for ToC/ToGC (3.x) [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]