this post was submitted on 19 Apr 2024
28 points (83.3% liked)

Privacy

31954 readers
518 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

I noticed that Quad 9 is not able to respond to the spy.pet query:

$ dig spy.pet @9.9.9.9 +short
;; communications error to 9.9.9.9#53: timed out

But Cloudflare DNS is able to do it:

$ dig spy.pet @1.1.1.1 +short
104.26.0.165
104.26.1.165
172.67.74.73

And to be sure, I checked another domain with the same TLD to rule out the option that Quad9 is unable to handle the .pet TLD, but I received a correct answer...

$ dig hello.pet @9.9.9.9 +short
3.64.163.50

Does Quad9 censor DNS queries?

you are viewing a single comment's thread
view the rest of the comments
[–] riplin@lemm.ee 4 points 6 months ago (1 children)

Governments don’t ask. They order. And it happens on a regular basis.

[–] TCB13@lemmy.world -2 points 6 months ago (1 children)

Yes, but if the provider doesn't have the capabilities baked in they'll take more time to comply or just not do it at all.

[–] riplin@lemm.ee 4 points 6 months ago (1 children)

You really don’t want to ignore an order from a judge. And blocking websites is trivial.

[–] TCB13@lemmy.world -2 points 6 months ago* (last edited 6 months ago) (1 children)

And blocking websites is trivial.

Nothing is trivial at scale. When we’re talking about Quad9, Cloudflare etc. were talking about hundreds of servers across the planet, highly distributed solutions that rely on multicast and other non-trivial techniques. If you’ve to change a system like that to add the ability to block something, trust me, it won’t take a few hours and a LOT of testing will be required before pushing into production.

[–] AmbiguousProps@lemmy.today 3 points 6 months ago (1 children)

The ability to change address records at global scale is built into DNS. It's not a new thing.

[–] TCB13@lemmy.world -3 points 6 months ago (1 children)

Nothing is "built into DNS". DNS is a couple of RFCs that include specifications on how the thing should work. What features one implementation (software) has is decision of those who made it and nothing else.

[–] AmbiguousProps@lemmy.today 2 points 6 months ago* (last edited 6 months ago)

What you said here is not really on topic, but it is literally part of DNS. I already explained it in my other comment, but here:

DNS, by design, uses authoritative nameservers, which is what cloudflare and quad9 host. These authoritative hosts distribute their records to caches (usually just recursive DNS resolvers) to ease and distribute the load. It's literally in all of their documentation, and explained in pretty plain english on their pages.

https://www.cloudflare.com/learning/dns/what-is-dns/

https://www.quad9.net/about/

Much of the Quad9 platform is hosted on infrastructure that supports authoritative DNS for approximately one-fifth of the world’s top-level domains, two root nameservers, and which sees billions of requests per day.

When a record is updated in your domain (or cloud) provider, it is distributed via an authoritative nameserver hosted by that company. These get distributed to the root name servers, which then distribute the records to other authoritative nameservers.