republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Post a:
Post a:
AuthorAll Replies


davidu

join:2006-12-28
San Francisco, CA

reply to fcisler

Re: OPENDNS

said by fcisler:

It IS a hack as there is NO, read it, NO, means for authentication via DNS. In otherwords - when I request a result from OpenDNS - it is identical to YOUR request, with the exception of our IP address'.

Now...it IS a hack that they will then have THEIR DNS SERVER check a database to find MY IP to find that I OPTED OUT of their bogus domain forwarding.

You are completely off in your assumption - I don't see OpenDNS as having ANY OTHER WAY to "fix" the results than those steps posted. If you have any other inside info - please post it.....but I don't ever recall seeing ANY OTHER DNS do that, unless specifically designed to.
There's more than just your IP address. There's the query_id mux'd in there along with some other request-specific bits that make it hard to forge a reply from us. That said, this is NO different from the way any other DNS server works. UDP is stateless and that's the name of the game.

That said, we do base preferences on your src_addr. It works very very well. It's not at all a hack just because it's new to you. It was far from a quick job and it does the job well. So well in fact that others are trying to figure out how to emulate it, including BIND.

-david

Monday, 28-May 12:00:50 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics