Re: enough is enough
Mark Andrews <[email protected]> Mon, 22 Dec 2014 15:06:53 +1100
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
In message <[email protected]>, Jim Reid writes: > On 21 Dec 2014, at 09:44, bert hubert <[email protected]> wrote: > > > This would then come with a website with further explanations, and > perhaps > > even a registry of faults that has been decided we're not going to fix. > > Bert, your prototype email is all very well. Of course it would be nice > if there was some botnet (say) which went looking for these broken DNS > servers and sent an email from the aa=0 police like the one you suggested. > > However this is howling at the moon. For decades the DNS industry has > been unable to get people to fix their lame delegations or get them to > stop using BIND8 or to use software which does EDNS or... So an attempt > along these lines to fix the aa=0 problem will be yet another Epic Fail. > If DNS lameness can't be cured, contacting registrants -- assuming that > was possible and it isn't -- to get software replaced surely won't > succeed either. To my knowledge no one has attempted to get nameservers upgraded by sending email to delegated server operators. Sending email to TLD operators does have a effect. Whether that can be replicated the next level down we need to see. Additionally classic lameness will come back over time as it is a configuration issue. Once you fix software it stays fixed. The more TLD operators that come on board the more likely it is to succeed. A DNS hosters getting complaints from all TLD operators is much more likely to pay attention to them. Similarly individual operators in multiple TLDs. > Everyone here should already know by now that contacting registrants en > masse will never produce the desired outcome. We should also know why > that approach is guaranteed to fail every time. Now who was it that said > "The definition of insanity is doing the same thing over and over again, > but expecting different results"? > The only sensible approach to take here is to notify the vendors of the > broken software and hope they do the Right Thing. If they don't, or their > customers can't/won't upgrade, the rest of us just have to suck it up. > 'Twas ever thus. At least the DNS developer community is small and fairly > easy to reach. Vendors also need to fix their software and no the DNS developer community isn't small enough to reach everyone. Going through zone operators is the only way to reach some of the players. Ultimately the zone operators need to update their nameservers and firewalls to be DNS compliant. Expecting them to learn that the need to update without a active campain will fail. > BTW, your Subject: header is appropriate. There's been more than enough > discussion of this deeply flawed approach to fixing the aa=0 problem. > _______________________________________________ > dnsext mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/dnsext -- Mark Andrews, ISC 1 Seymour St., Dundas Valley, NSW 2117, Australia PHONE: +61 2 9871 4742 INTERNET: [email protected] _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext